<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/fake-it-support-calls-on-microsoft-teams-push-etherrat-malware-jxemdaeql" -->

---
title: Fake IT support calls on Microsoft Teams push EtherRAT...
description: Threat actors are conducting vishing attacks via Microsoft Teams, impersonating corporate IT support to trick employees into installing EtherRAT malware. The...
canonical: https://daily.dev/posts/fake-it-support-calls-on-microsoft-teams-push-etherrat-malware-jxemdaeql
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Fake IT support calls on Microsoft Teams push EtherRAT malware | daily.dev
og:description: Threat actors are conducting vishing attacks via Microsoft Teams, impersonating corporate IT support to trick employees into installing EtherRAT malware. The...
og:url: https://daily.dev/posts/fake-it-support-calls-on-microsoft-teams-push-etherrat-malware-jxemdaeql
og:image: https://api.daily.dev/og/posts/JxEMdaeqL.png
og:image:alt: Fake IT support calls on Microsoft Teams push EtherRAT malware
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Fake IT support calls on Microsoft Teams push EtherRAT malware

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 0 upvotes · 0 comments

## Summary

Threat actors are conducting vishing attacks via Microsoft Teams, impersonating corporate IT support to trick employees into installing EtherRAT malware. The campaign, uncovered by Palo Alto Networks' Unit 42, starts with a phishing email containing a malicious PDF, followed by a Teams voice call from an external account posing as a System Administrator. Attackers gain remote access through legitimate tools like HopToDesk and AnyDesk, then deploy a Node.js-based malware loader that installs EtherRAT — a cross-platform RAT that uses Ethereum smart contracts for C2 communication, making it difficult to disrupt. Multiple versioned installers found on an open directory suggest the campaign is actively evolving. Microsoft has been adding new Teams protections in response to a growing wave of similar helpdesk impersonation attacks.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/fake-it-support-calls-on-microsoft-teams-push-etherrat-malware>

## Similar posts on daily.dev

- [Fake IT bods on Microsoft Teams coax workers into installing malware](https://daily.dev/posts/fake-it-bods-on-microsoft-teams-coax-workers-into-installing-malware-ug5zbhdoi) · The Register · 0 upvotes · 0 comments
- [Watch out for fake support calls in Microsoft Teams](https://daily.dev/posts/watch-out-for-fake-support-calls-in-microsoft-teams-dytpwjqgk) · CSO Online · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/fake-it-support-calls-on-microsoft-teams-push-etherrat-malware-jxemdaeql)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Fake IT support calls on Microsoft Teams push EtherRAT malware","url":"https://daily.dev/posts/fake-it-support-calls-on-microsoft-teams-push-etherrat-malware-jxemdaeql","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/fake-it-support-calls-on-microsoft-teams-push-etherrat-malware-jxemdaeql"},"datePublished":"2026-07-06T20:24:04.785Z","dateModified":"2026-07-06T20:24:25.470Z","description":"Threat actors are conducting vishing attacks via Microsoft Teams, impersonating corporate IT support to trick employees into installing EtherRAT malware. The...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/8189dabd066d9f9a1af5c205aa387382?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/8189dabd066d9f9a1af5c205aa387382?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/fake-it-support-calls-on-microsoft-teams-push-etherrat-malware-jxemdaeql","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,malware","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"Fake IT support calls on Microsoft Teams push EtherRAT malware"}]}
```

