highPhishing

EtherRAT Malware via Fake Microsoft Teams IT Support Calls

First seen Jul 7, 2026 · Updated Jul 7, 2026

vishingteams-abusesocial-engineeringinitial-accessratremote-access-trojanhelp-desk-impersonationagent-relevant

Threat actors are impersonating corporate IT support staff over Microsoft Teams voice calls to socially engineer employees into installing the EtherRAT remote access trojan. Once installed, the malware grants attackers initial access to corporate networks, potentially enabling lateral movement, credential theft, and further compromise. This campaign leverages trust in internal communication tools rather than exploiting a software vulnerability.

Technical Analysis

The attack chain begins with a vishing call over Microsoft Teams where the attacker poses as internal IT support, instructing the victim to run a remote-access tool or script under the guise of troubleshooting. This results in deployment of EtherRAT, a remote access trojan providing attackers with persistent backdoor access, command execution, and likely credential/session harvesting capabilities on the compromised endpoint. No CVE or software exploit is involved; the vector is pure social engineering combined with abuse of legitimate collaboration software features (e.g., screen sharing, remote control permissions in Teams). Once inside the network, attackers can pivot to systems hosting sensitive data, including developer workstations and servers running AI agent frameworks, RAG pipelines, or LLM orchestration tools, where stolen credentials, API keys, or session tokens could be exfiltrated and used to hijack agent-to-tool integrations or exfiltrate proprietary model/data assets. Organizations running AI agents with broad system permissions or stored API keys on employee endpoints are at elevated risk if such an endpoint is compromised via this vector.

Affected Systems

Windows endpoints running Microsoft Teams client with remote control/screen-sharing enabled; corporate networks lacking call-verification/IT impersonation controls; any endpoint where employees have local admin rights to install unsigned executables.

Indicators of Compromise

  • EtherRAT malware payload (specific hash not disclosed in source reporting)
  • Microsoft Teams caller IDs/display names impersonating IT support (details not disclosed)
  • Suspicious remote-control session initiation via Teams screen sharing

Remediation Steps

  1. 1

    Restrict Teams remote control features

    Disable or tightly restrict Teams screen control/remote assistance features via admin policy, especially for calls from external or unverified tenants.

  2. 2

    Enforce IT support verification procedures

    Implement out-of-band verification (e.g., ticket number lookup, callback to known IT extension) before employees accept remote troubleshooting help.

  3. 3

    Deploy endpoint detection and response (EDR)

    Ensure EDR is active on all endpoints to detect and block RAT installation, unauthorized remote access tools, and anomalous process execution.

  4. 4

    Restrict local admin rights

    Limit standard users' ability to install unsigned or unapproved executables to reduce malware installation success.

  5. 5

    User awareness training

    Train employees to recognize vishing/impersonation attempts via Teams and other collaboration platforms, emphasizing that legitimate IT rarely cold-calls to request software installs.

  6. 6

    Rotate and audit credentials/API keys

    For any compromised endpoint, rotate stored credentials, session tokens, and API keys (including those used by AI agents or automation tools) and audit for unauthorized use.

  7. 7

    Enable Teams external access controls

    Restrict or monitor external tenant communication in Microsoft Teams to reduce exposure to impersonation calls from outside the organization.

Industries Most Exposed

cross-industryenterprisetechnologyfinancehealthcare

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.