Cybercriminals Exploit Microsoft Teams Calls to Deploy EtherRAT Malware

Cybercriminals launch a sophisticated attack campaign that combines phishing emails with fake Microsoft Teams voice calls to infiltrate corporate networks. Posing as internal IT support staff, the attackers send targets a malicious PDF disguised as an employee survey. Shortly after the victim opens the document, the attacker initiates a Teams call from an external account and convinces the employee to grant remote screen-sharing access.

Once connected, the intruders guide the victim through installing legitimate remote management tools like AnyDesk and HopToDesk. With full remote control established, the attackers download and execute a malicious installer that deploys a Node.js runtime to decrypt and launch EtherRAT. This cross-platform remote access trojan gives attackers complete control over the compromised system, allowing them to execute commands, steal sensitive data, and maintain long-term persistence without detection.

EtherRAT stands out for its clever use of Ethereum smart contracts to retrieve its command-and-control server addresses, a technique that makes the malware's communication channels notoriously difficult to shut down. Security researchers at Palo Alto Networks' Unit 42 discover multiple versions of the malware on distribution servers, signaling active and ongoing development. The growing trend of Teams-based attacks underscores the critical need for organizations to restrict external communications and train employees to verify caller identities.

Read More at the original source →