Fake IT bods on Microsoft Teams coax workers into installing malware
ID: a077b0a2-96c9-5863-b30b-59c291dc1b78
STIX ID: report--a077b0a2-96c9-5863-b30b-59c291dc1b78
Feed Name: The Register (Security)
Unit 42 reports a campaign where attackers send phishing emails and then place fake Microsoft Teams IT-support calls to trick employees into granting remote control and installing an MSI that deploys EtherRAT, a Node.js cross-platform remote access trojan that fetches C2 from an Ethereum smart contract. Researchers observed Teams session artifacts (files beginning with "CtrlVirtualCursorWin_*") as a forensic indicator, confirmed cross-tenant OneOnOne chat abuse, and found an open repository containing EtherRAT versions through v9, indicating ongoing development.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
