bleeping-computer · Crawled Jul 6, 2026
Fake IT support calls on Microsoft Teams push EtherRAT malware
4 IoCs 1 Malware
Read original article ↗
AI Summary
Threat actors are conducting fake IT support calls via Microsoft Teams to trick employees into installing the EtherRAT malware. The attack begins with a phishing email containing a malicious PDF, followed by a voice call from an external Teams account impersonating system administrators. Attackers use legitimate remote access tools like HopToDesk and AnyDesk, then deploy EtherRAT via a malicious MSI installer, enabling full system control and data theft. EtherRAT uses Ethereum smart contracts for C2 resilience, and the campaign is actively evolving with multiple malware versions observed.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 4 extracted
MITRE ATT&CK TTPs 37 techniques
T1016 System Network Configuration Discovery · Discovery T1021.001 Remote Desktop Protocol · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1053.005 Scheduled Task · Execution T1055 Process Injection · Defense Evasion T1055.012 Process Hollowing · Defense Evasion T1056.003 Web Portal Capture · Collection T1059.001 PowerShell · Execution T1059.007 JavaScript · Execution T1070.004 File Deletion · Defense Evasion T1071.001 Web Protocols · Command And Control T1071.004 DNS · Command And Control T1074.001 Local Data Staging · Collection T1078 Valid Accounts · Defense Evasion T1080 Taint Shared Content · Lateral Movement T1082 System Information Discovery · Discovery T1085 T1085 T1087.002 Domain Account · Discovery T1090.004 Domain Fronting · Command And Control T1095 Non-Application Layer Protocol · Command And Control T1098.004 SSH Authorized Keys · Persistence T1105 Ingress Tool Transfer · Command And Control T1113 Screen Capture · Collection T1133 External Remote Services · Persistence T1202 Indirect Command Execution · Defense Evasion T1204.002 Malicious File · Execution T1210 Exploitation of Remote Services · Lateral Movement T1212 Exploitation for Credential Access · Credential Access T1484.001 Group Policy Modification · Defense Evasion T1485 Data Destruction · Impact T1496 Resource Hijacking · Impact T1548 Abuse Elevation Control Mechanism · Privilege Escalation T1555 Credentials from Password Stores · Credential Access T1557.001 LLMNR/NBT-NS Poisoning and SMB Relay · Credential Access T1558.003 Kerberoasting · Credential Access T1566 Phishing · Initial Access T1647 Plist File Modification · Defense Evasion