ShellCodeX
Tools • Events • News • Insights
SEO Checker
ShellCodeX Intelligence Brief
CRITICAL Cybersecurity

Teams voice impersonation tricks users into installing EtherRAT malware

Source headline: Fake IT support calls on Microsoft Teams push EtherRAT malware

Threat level Critical
Signal strength 80/100
Source confidence 1 source
Published 1 month ago

Intelligence Summary

Attackers are abusing Microsoft Teams voice calls to impersonate corporate IT support. The scam targets employees and persuades them to install the EtherRAT malware. Once installed, the malware can provide attackers initial access to corporate environments. This creates a pathway for further intrusion, data theft, and lateral movement. Users should be cautious of unexpected Teams calls requesting software installs and verify requests through official IT channels.

Recommended Action

Inventory where Microsoft Teams runs in your environment and treat this as an active remediation item. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.

Topics

#malware #social-engineering #microsoft-teams #initial-access #etherrat #voice-call-impersonation
Original reporting BleepingComputer Fake IT support calls on Microsoft Teams push EtherRAT malware
Open original source