bleeping-computer · Crawled Jul 6, 2026
Fake IT support calls on Microsoft Teams push EtherRAT malware
4 IoCs 1 Malware
Read original article ↗
AI Summary
Threat actors are conducting fake IT support calls via Microsoft Teams to trick employees into installing the EtherRAT malware. The attack begins with a phishing email containing a malicious PDF, followed by a voice call from an external Teams account impersonating system administrators. Attackers use legitimate remote access tools like HopToDesk and AnyDesk, then deploy EtherRAT via a malicious MSI installer, enabling full system control and data theft. EtherRAT uses Ethereum smart contracts for C2 resilience, and the campaign is actively evolving with multiple malware versions observed.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 4 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | camorreado[[.]]click | Details → |
| Filename | v7.msi | Details → |
| GitHub Repo | unit42/poc | Details → |
| Registry User | [email protected][.]com | Details → |
MITRE ATT&CK TTPs 15 techniques
T1027 Obfuscated Files or Information · Defense Evasion T1055.012 Process Hollowing · Defense Evasion T1059.001 PowerShell · Execution T1059.007 JavaScript · Execution T1071.001 Web Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1085 T1085 T1133 External Remote Services · Persistence T1202 Indirect Command Execution · Defense Evasion T1204.002 Malicious File · Execution T1212 Exploitation for Credential Access · Credential Access T1484.001 Group Policy Modification · Defense Evasion T1548 Abuse Elevation Control Mechanism · Privilege Escalation T1558.003 Kerberoasting · Credential Access T1566 Phishing · Initial Access