logo

Fake IT bods on Microsoft Teams coax workers into installing malware

ID: a077b0a2-96c9-5863-b30b-59c291dc1b78

STIX ID: report--a077b0a2-96c9-5863-b30b-59c291dc1b78

Feed Name: The Register (Security)

Threat Score
65/100

Date Published: 2026-07-07

Date Updated: 2026-07-23

...
...

Unit 42 reports a campaign where attackers send phishing emails and then place fake Microsoft Teams IT-support calls to trick employees into granting remote control and installing an MSI that deploys EtherRAT, a Node.js cross-platform remote access trojan that fetches C2 from an Ethereum smart contract. Researchers observed Teams session artifacts (files beginning with "CtrlVirtualCursorWin_*") as a forensic indicator, confirmed cross-tenant OneOnOne chat abuse, and found an open repository containing EtherRAT versions through v9, indicating ongoing development.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.