Microsoft Teams abused to fake IT support and deliver EtherRAT malware to businesses
- Evelyn Carter

- Jul 8
- 3 min read
A new attack campaign is abusing Microsoft Teams voice calls to impersonate IT support staff and trick users into installing EtherRAT malware. Attackers combine phishing emails, Teams calls, and legitimate remote access tools to gain initial access to business systems.
As Microsoft Teams becomes a common business communication platform, cybercriminals are also exploiting users’ trust in internal collaboration tools. The newly reported EtherRAT campaign shows that a single fake IT support call can create an entry point into a business system if employees are not alert.
How is Microsoft Teams being abused to deliver EtherRAT?
This campaign does not exploit a Microsoft Teams vulnerability. Instead, it relies on social engineering by impersonating IT support staff to gain the victim’s trust.
The attack begins with a phishing email containing a malicious PDF file. After that, the victim receives a Microsoft Teams call from an external account claiming to be from IT support.

During the call, the victim is instructed to install legitimate remote access tools such as AnyDesk or HopToDesk to “fix an issue.” Once remote access is granted, the attacker deploys a malicious MSI installer that downloads the Node.js runtime, decrypts malware components, and finally activates EtherRAT on the victim’s device.
Why is EtherRAT dangerous for businesses?
EtherRAT is malware that allows attackers to maintain remote access after a successful intrusion.
Based on the reported information, the goal of the campaign is to establish initial access into corporate networks. Once inside the system, attackers may continue expanding their attack or perform follow-up actions.
Why are fake IT support calls becoming more effective?
Collaboration platforms like Microsoft Teams are now part of daily business operations. This makes employees less suspicious when receiving a call from someone claiming to be technical support.
Microsoft has also previously warned that attackers are increasingly abusing Teams for helpdesk impersonation campaigns, combining fake support interactions with legitimate remote access software to gain system access.
By abusing internal support workflows, attackers can bypass user suspicion and security checks when businesses do not have identity verification procedures before granting remote access.
What should businesses do to prevent this type of attack?
The most important step is to establish a verification process for every technical support request.
Businesses should:
Avoid installing remote access software based on instructions from unexpected calls.
Verify the caller’s identity through official internal channels.
Restrict or control calls from external Microsoft Teams accounts.
Train employees to recognize fake IT helpdesk calls.
Monitor unusual installation of remote access tools and MSI files on endpoints.
These measures can reduce the risk of attacks that exploit human trust instead of technical vulnerabilities.

Actions businesses can take immediately in-house
For social engineering campaigns involving Microsoft Teams, employees are the first layer of defense.
IPSIP recommends that businesses:
Create a multi-step helpdesk verification process before granting computer control.
Apply Zero Trust principles to all remote access requests.
Limit software installation privileges for regular users.
Monitor unusual processes such as AnyDesk, HopToDesk, or MSI Installer outside approved workflows.
Conduct regular training exercises on identifying fake support calls.
In reality, helpdesk impersonation attacks often happen quickly and are difficult to detect without continuous security monitoring.
Protecting your "digital infrastructure" with IPSIP Vietnam
IPSIP Vietnam's management and monitoring platform has successfully passed rigorous independent assessments to achieve internationally recognized ISO/IEC 27001:2022 and SOC 2 Type II certifications. Through its 24/7 Security Operations Center (SOC), 24/7 Network Operations Center (NOC), and dedicated IT Support/Helpdesk teams, IPSIP delivers continuous monitoring, rapid threat detection, and around-the-clock incident response to help organizations defend against cyber threats at any time.

The EtherRAT campaign shows that attackers do not always need to exploit software vulnerabilities. Increasingly, they exploit user trust. A single Microsoft Teams call pretending to be IT support can become the starting point of a serious security incident. Businesses should strengthen user awareness, standardize technical support procedures, and deploy appropriate security monitoring layers to reduce risks from increasingly sophisticated social engineering attacks.
Reference










Comments