bleeping-computer · Crawled Jul 6, 2026

Fake IT support calls on Microsoft Teams push EtherRAT malware

4 IoCs 1 Malware
Read original article ↗

AI Summary

Threat actors are conducting fake IT support calls via Microsoft Teams to trick employees into installing the EtherRAT malware. The attack begins with a phishing email containing a malicious PDF, followed by a voice call from an external Teams account impersonating system administrators. Attackers use legitimate remote access tools like HopToDesk and AnyDesk, then deploy EtherRAT via a malicious MSI installer, enabling full system control and data theft. EtherRAT uses Ethereum smart contracts for C2 resilience, and the campaign is actively evolving with multiple malware versions observed.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 4 extracted

Type Value Detail
Domain camorreado[[.]]click Details →
Filename v7.msi Details →
GitHub Repo unit42/poc Details →
Registry User [email protected][.]com Details →

MITRE ATT&CK TTPs 15 techniques