LIVE · cybersecurity feed
Live wire
malware

Fake IT support calls on Microsoft Teams push EtherRAT malware

Threat actors are abusing Microsoft Teams voice calls by impersonating corporate IT support staff to trick employees into installing the EtherRAT malware, giving attackers initial access to corporate networks. [...]

zeroday.news · 26d ago

Threat actors are leveraging Microsoft Teams voice calls to impersonate IT support staff and trick employees into installing the EtherRAT malware, according to research from Palo Alto Networks' Unit 42. This tactic grants attackers initial access to corporate networks. The operation combines phishing emails, Teams voice calls, legitimate remote management tools, and a custom malware loader to compromise victim systems.

The attack sequence begins with a phishing email containing a lure such as an "Employee Survey" and a malicious PDF attachment. Upon opening the document, the targeted employee receives a Microsoft Teams voice call. The caller impersonates a "System Administrator" and is identified as an external party, indicating they are from a different Microsoft 365 tenant. Audit logs revealed an attacker initiated a chat using an external account, helpdesk@Progressive936.onmicrosoft[.]com, while posing as IT support.

After convincing the victim to share their screen via Microsoft Teams, the attacker guides them through installing legitimate remote access tools like HopToDesk and AnyDesk. Once remote access is established, the attackers download and execute a malicious MSI installer from camorreado[.]click. This MSI file functions as a malware loader. It downloads a legitimate Node.js runtime, decrypts embedded malicious payloads, and ultimately deploys EtherRAT.

EtherRAT is a cross-platform remote access trojan developed in Node.js. It provides attackers with comprehensive control over compromised systems, enabling them to execute commands, manipulate files, exfiltrate data, and establish persistence. A notable feature of EtherRAT is its use of Ethereum smart contracts to retrieve its active command-and-control server information, which complicates efforts to disrupt its operations. This malware has previously been associated with state-sponsored attacks and has since been adopted by various other threat groups.

Unit 42 researchers discovered an open directory on a distribution server containing multiple versions of the malware installers, from v1 to v9. This suggests the ongoing development and active use of this campaign.

This latest campaign highlights a growing trend of attackers exploiting Microsoft Teams to breach corporate networks. In March, a similar campaign targeted financial and healthcare organizations by using spam emails followed by Teams calls from individuals impersonating IT staff. Victims in that instance were persuaded to launch Quick Assist sessions, which led to the deployment of the A0Backdoor malware.

In April, Microsoft issued a warning about attackers increasingly using external Microsoft Teams accounts to impersonate helpdesk personnel. These attackers would then convince employees to grant them remote access to their devices. Once inside a network, these threat actors would conduct reconnaissance, spread to other devices, and steal data.

Microsoft has been implementing new protections within Teams to counter these evolving threats. Earlier this year, the company introduced warnings to identify external callers and chats, aiming to protect users from potential phishing and vishing attacks. More recently, Microsoft introduced a new administrator policy for Teams that automatically places suspected third-party bots into the meeting lobby, requiring manual approval from organizers before they can join.

malware
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.

vulnerability

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]