Threat actors are impersonating corporate IT support staff over Microsoft Teams voice calls to socially engineer employees into installing the EtherRAT remote access trojan. Once installed, the malware grants attackers initial access to corporate networks, potentially enabling lateral movement, credential theft, and further compromise. This campaign leverages trust in internal communication tools rather than exploiting a software vulnerability.
Updated Jul 7, 2026