The fake IT-support campaign abusing Microsoft Teams shows how attackers are shifting from email phishing to direct social engineering through trusted collaboration platforms.
Threat actors impersonate corporate IT support staff and call employees over Microsoft Teams, convincing them to install what appears to be a legitimate support or troubleshooting tool. In reality, the installation deploys EtherRAT malware and gives attackers remote access to the victim’s computer.
The attack is effective because it uses a familiar business platform and a believable support scenario. Employees may trust the call because it appears inside Microsoft Teams rather than through a suspicious email or unknown website. Apparently, putting the scam inside a corporate app gives it just enough office furniture to look respectable.
Organizations should restrict external Teams communication where it is not required, clearly define how IT support contacts employees, and train users to verify unexpected support calls through a separate approved channel.
Security teams should monitor for unusual Teams contact from external accounts, unexpected remote-access tools, suspicious downloads, PowerShell activity, new persistence mechanisms, and outbound connections following a support interaction.
The key lesson is that trusted collaboration tools can become phishing channels. A Teams call from someone claiming to be IT support should not be trusted unless it matches the organization’s approved support process.
Threat actors are abusing Microsoft Teams voice calls by impersonating corporate IT support staff to trick employees into installing the EtherRAT malware, giving attackers initial access to corporate networks. [...]
Source: Fake IT support calls on Microsoft Teams push EtherRAT malware via Bleeping Computer — published 06 Jul 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.