
Cybercriminals Impersonate IT Support via Microsoft Teams to Deploy EtherRAT Malware
cybersecuritymalwaremicrosoftteamssocial_engineering
Researchers from Unit 42 identified a social engineering campaign where attackers impersonate IT support staff via Microsoft Teams to trick employees into installing the EtherRAT malware on Windows systems. The threat actors initiate fake support calls, leveraging the platform’s communication features to gain trust and deploy the remote access trojan. No specific dates, affected versions, or technical indicators (e.g., CVE IDs) were disclosed in the report. The malware enables unauthorized access and control over compromised endpoints, though the exact impact on victims remains unspecified. The attack vector exploits human interaction rather than a software vulnerability.