{"id":951,"date":"2026-07-08T12:23:19","date_gmt":"2026-07-08T06:53:19","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=951"},"modified":"2026-08-19T12:27:52","modified_gmt":"2026-08-19T06:57:52","slug":"microsoft-teams-etherrat-phishing","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/microsoft-teams-etherrat-phishing\/","title":{"rendered":"Microsoft Teams EtherRAT Phishing Uses Fake IT Support Calls to Deliver Malware"},"content":{"rendered":"<h2>Microsoft Teams is becoming a new channel for social engineering<\/h2>\n<p>Attackers continue to adapt their tactics as organizations rely more heavily on collaboration platforms. A recently disclosed Microsoft Teams EtherRAT Phishing campaign demonstrates how Microsoft Teams can be abused as a trusted communication channel to impersonate corporate IT support and persuade employees to install remote access software before deploying EtherRAT malware.<\/p>\n<p>Rather than exploiting a flaw in Microsoft Teams, the attackers reportedly rely on phishing, voice-based social engineering, and legitimate administration tools to gain hands-on access to enterprise endpoints. The campaign illustrates how trusted business workflows can become an effective initial access vector when combined with convincing impersonation.<\/p>\n<p>For security teams, the incident reinforces an important lesson: protecting collaboration platforms requires more than email filtering. Organizations also need clear support verification procedures, application controls, endpoint visibility, and identity-based access policies.<\/p>\n<p><center>    \t\t<!-- button style scb20be917a3efc78059cf9961ee4e54284 -->\r\n    \t\t<style>\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284, a.scb20be917a3efc78059cf9961ee4e54284{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: #00868B;\r\n    \t\t\t}\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284:hover, a.scb20be917a3efc78059cf9961ee4e54284:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #32b8bd;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/xdr\/\" class=\"ht-shortcodes-button scb20be917a3efc78059cf9961ee4e54284  hn-cta__blogs--inline-button \" id=\"\" style=\"\" target=\"_blank\">\r\n    \t\tExplore Hexnode XDR<\/a>\r\n    \t\t<\/center><\/p>\n<h2>How the Microsoft Teams EtherRAT attack works<\/h2>\n<p>Public reporting indicates that the campaign follows a carefully orchestrated sequence designed to build trust before malware is delivered.<\/p>\n<h3>1. A phishing email initiates the attack<\/h3>\n<p>The campaign begins with a <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-phishing\/\">phishing<\/a> email using an Employee Survey lure that contains a malicious PDF attachment.<\/p>\n<h3>2. The victim receives a fake IT support call<\/h3>\n<p>After the document is opened, the employee reportedly receives a Microsoft Teams voice call from an external Microsoft 365 tenant. The caller impersonates a System Administrator or internal IT support representative.<\/p>\n<h3>3. Remote control is established<\/h3>\n<p>During the call, the attacker persuades the employee to:<\/p>\n<ul>\n<li>Share their screen through Microsoft Teams<\/li>\n<li>Grant remote control<\/li>\n<li>Install legitimate remote administration software such as:<\/li>\n<li>AnyDesk<\/li>\n<li>HopToDesk<\/li>\n<\/ul>\n<p>Because these applications are commonly used for legitimate remote support, employees may perceive the request as routine.<\/p>\n<h3>4. EtherRAT is deployed<\/h3>\n<p>Once remote access has been established, the attacker downloads and executes a malicious MSI installer hosted on camorreado[.]click.<\/p>\n<p>The installer:<\/p>\n<ul>\n<li>Downloads a legitimate Node.js runtime<\/li>\n<li>Decrypts embedded payloads<\/li>\n<li>Executes EtherRAT on the compromised endpoint<\/li>\n<\/ul>\n<p>At the time of writing, the threat actor has not been publicly identified, and no victim organizations have been publicly disclosed.<br \/>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/The-Ultimate-Guide-to-XDR-Extended-Detection-and-Response.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>The Ultimate Guide to XDR (Extended Detection and Response)<\/h4><p>Learn how XDR unifies threat detection, investigation, and response to strengthen enterprise security.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/xdr-extended-detection-and-response\/\" aria-label=\"The Ultimate Guide to XDR (Extended Detection and Response)\"><\/a><\/div><\/div><\/div><\/p>\n<h2>What is EtherRAT?<\/h2>\n<p>EtherRAT is a Node.js-based <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-remote-access-trojan-rat-in-cyber-security\/\">remote access trojan<\/a> (RAT) designed to provide persistent remote control of compromised systems.<\/p>\n<p>According to public reporting, its capabilities include:<\/p>\n<ul>\n<li>Remote command execution<\/li>\n<li>File management<\/li>\n<li>Persistence<\/li>\n<li>Data theft functionality<\/li>\n<li>Retrieval of active <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-command-and-control-c2\/\">command-and-control (C2)<\/a> infrastructure through Ethereum smart contracts<\/li>\n<\/ul>\n<p>Using Ethereum smart contracts to locate command-and-control infrastructure may make the malware more resilient by allowing operators to update infrastructure without relying solely on hardcoded domains.<\/p>\n<p>Although EtherRAT includes data theft capabilities, there has been no public confirmation that credentials were stolen or that data was exfiltrated in this campaign.<\/p>\n<h2>Why attackers are abusing Microsoft Teams<\/h2>\n<p>The campaign highlights a broader shift in attacker behavior. Rather than targeting software vulnerabilities, attackers increasingly exploit trusted communication channels and familiar business processes.<\/p>\n<p>Several factors make Microsoft Teams an attractive platform for <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-social-engineering\/\">social engineering<\/a>:<\/p>\n<ul>\n<li>Employees often expect legitimate IT support interactions through collaboration tools.<\/li>\n<li>Voice conversations can appear more credible than phishing emails alone.<\/li>\n<li>Live interaction enables attackers to answer questions and build trust in real time.<\/li>\n<li>Legitimate remote administration software helps disguise malicious activity as routine technical support.<\/li>\n<\/ul>\n<p>The campaign does not indicate a vulnerability in Microsoft Teams itself. Instead, it demonstrates how attackers can abuse legitimate platform features and user trust to gain access to enterprise endpoints.<\/p>\n<h2>Enterprise security lessons from this campaign<\/h2>\n<p>Organizations should view this incident as an opportunity to strengthen both technical controls and employee awareness.<\/p>\n<h3>Verify unsolicited IT support requests<\/h3>\n<p>Employees should be encouraged to independently verify unexpected support calls before granting screen sharing, remote control, or software installation permissions.<\/p>\n<h3>Control remote administration software<\/h3>\n<p>Remote access applications should be limited to approved tools and authorized workflows. Managing approved applications and identifying unauthorized remote administration tools can reduce opportunities for attackers to abuse legitimate software.<\/p>\n<h3>Monitor endpoint activity after remote sessions<\/h3>\n<p>Unexpected software installation, unusual process execution, or persistence mechanisms following a remote support session should be investigated promptly.<\/p>\n<h3>Review Microsoft Teams external communication policies<\/h3>\n<p>Organizations should review external Teams communication settings and ensure employees understand how to identify external callers impersonating internal support personnel.<\/p>\n<h2>How Hexnode can help reduce the risk<\/h2>\n<p>While no platform can eliminate social engineering, layered endpoint and identity controls can help reduce the impact of attacks like this one.<\/p>\n<h3>Strengthen endpoint governance with Hexnode UEM<\/h3>\n<p><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> can help organizations:<\/p>\n<ul>\n<li>Manage approved applications across enterprise devices<\/li>\n<li>Apply blocklist and <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-an-allowlist\/\">allowlist<\/a> policies where supported<\/li>\n<li>Identify unauthorized applications on Windows devices through Application Compliance<\/li>\n<li>Maintain visibility into applications installed on managed endpoints<\/li>\n<li>Enforce device compliance policies<\/li>\n<\/ul>\n<p>These capabilities can help organizations govern approved applications and identify unauthorized remote administration tools on managed endpoints.<br \/>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Making-XDR-Accessible-thumbnail-1-300x225-1.webp?format=webp\" class=\"resource-box__image\" alt=\"Making-XDR-Accessible-thumbnail-1-300x225\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Making-XDR-Accessible-thumbnail-1-300x225-1.webp?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Making-XDR-Accessible-thumbnail-1-300x225-1-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" title=\"Making-XDR-Accessible-thumbnail-1-300x225\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Making XDR Accessible for Every Team\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Discover how accessible XDR helps IT teams reduce alert fatigue and accelerate threat detection and response.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/white-papers\/making-xdr-accessible-for-every-team\/'>\n                            Download the whitepaper\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section><\/p>\n<h3>Investigate suspicious endpoint activity with Hexnode XDR<\/h3>\n<p>Following a suspected compromise, Hexnode XDR can help security teams:<\/p>\n<ul>\n<li>Detect suspicious endpoint activity<\/li>\n<li>Review historical endpoint events<\/li>\n<li>Respond through actions such as device isolation, process termination, or file quarantine<\/li>\n<\/ul>\n<p>These capabilities support endpoint-focused investigation and response after suspicious activity has been identified.<\/p>\n<h3>Reinforce access policies with Hexnode IdP<\/h3>\n<p><a href=\"https:\/\/www.hexnode.com\/idp\/\">Hexnode IdP<\/a> can complement endpoint security by supporting:<\/p>\n<ul>\n<li>Multi-factor authentication (MFA)<\/li>\n<li>Role-based access control (RBAC)<\/li>\n<li>Microsoft Entra ID integration<\/li>\n<li>Device compliance validation<\/li>\n<li>Basic conditional access based on device compliance<\/li>\n<\/ul>\n<p>Requiring compliant managed devices before users access business applications can provide an additional layer of protection following suspected social engineering incidents.<\/p>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Is Microsoft Teams vulnerable in this campaign?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>No. Based on publicly available reporting, the campaign abuses Microsoft Teams as a trusted communication channel through social engineering. There is no indication that attackers exploited a vulnerability in Microsoft Teams itself.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Does EtherRAT steal credentials?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Public reports describe data theft capabilities but do not confirm that attackers stole credentials during this campaign.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n<h3>Conclusion<\/h3>\n<p>The Microsoft Teams EtherRAT phishing campaign demonstrates how attackers increasingly rely on trusted collaboration platforms and human interaction rather than software vulnerabilities to compromise enterprise environments.<\/p>\n<p>By combining phishing emails, fake IT support calls, legitimate remote administration tools, and remote access malware, the <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/fake-it-support-calls-on-microsoft-teams-push-etherrat-malware\/?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=microsoft_teams_etherrat_phishing\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">campaign blurs the line between routine technical support and malicious activity<\/a>.<\/p>\n<p>Reducing the risk requires a layered approach that combines user awareness, application management, endpoint investigation, and identity-based access controls. As collaboration platforms continue to play a central role in enterprise operations, organizations should ensure that their security strategy extends beyond email to every trusted communication channel employees use.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Strengthen Your Endpoint Security Strategy<\/h5><p>See how Hexnode helps organizations manage endpoints, investigate suspicious activity, and enforce device compliance.<\/p><a href=\"https:\/\/www.hexnode.com\/xdr\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Sign up now<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft Teams is becoming a new channel for social engineering Attackers continue to adapt their&#8230;<\/p>\n","protected":false},"author":4,"featured_media":956,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[15,16],"class_list":["post-951","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-malware","category-windows","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Microsoft Teams EtherRAT Phishing: Fake IT Support Scam<\/title>\n<meta name=\"description\" content=\"Learn how the Microsoft Teams EtherRAT Phishing campaign works and how enterprises can reduce risk with Hexnode.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/microsoft-teams-etherrat-phishing\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Microsoft Teams EtherRAT Phishing: Fake IT Support Scam\" \/>\n<meta property=\"og:description\" content=\"Learn how the Microsoft Teams EtherRAT Phishing campaign works and how enterprises can reduce risk with Hexnode.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/microsoft-teams-etherrat-phishing\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-08T06:53:19+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-19T06:57:52+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Microsoft-Teams-EtherRAT-Phishing-Uses-Fake-IT-Support-Calls-to-Deliver-Malware.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"754\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Nora Blake\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nora Blake\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/microsoft-teams-etherrat-phishing\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/microsoft-teams-etherrat-phishing\\\/\"},\"author\":{\"name\":\"Nora Blake\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\"},\"headline\":\"Microsoft Teams EtherRAT Phishing Uses Fake IT Support Calls to Deliver Malware\",\"datePublished\":\"2026-07-08T06:53:19+00:00\",\"dateModified\":\"2026-08-19T06:57:52+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/microsoft-teams-etherrat-phishing\\\/\"},\"wordCount\":1112,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/microsoft-teams-etherrat-phishing\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Microsoft-Teams-EtherRAT-Phishing-Uses-Fake-IT-Support-Calls-to-Deliver-Malware.jpeg?format=webp\",\"articleSection\":[\"Malware\",\"Windows\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/microsoft-teams-etherrat-phishing\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/microsoft-teams-etherrat-phishing\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/microsoft-teams-etherrat-phishing\\\/\",\"name\":\"Microsoft Teams EtherRAT Phishing: Fake IT Support Scam\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/microsoft-teams-etherrat-phishing\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/microsoft-teams-etherrat-phishing\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Microsoft-Teams-EtherRAT-Phishing-Uses-Fake-IT-Support-Calls-to-Deliver-Malware.jpeg?format=webp\",\"datePublished\":\"2026-07-08T06:53:19+00:00\",\"dateModified\":\"2026-08-19T06:57:52+00:00\",\"description\":\"Learn how the Microsoft Teams EtherRAT Phishing campaign works and how enterprises can reduce risk with Hexnode.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/microsoft-teams-etherrat-phishing\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/microsoft-teams-etherrat-phishing\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/microsoft-teams-etherrat-phishing\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Microsoft-Teams-EtherRAT-Phishing-Uses-Fake-IT-Support-Calls-to-Deliver-Malware.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Microsoft-Teams-EtherRAT-Phishing-Uses-Fake-IT-Support-Calls-to-Deliver-Malware.jpeg?format=webp\",\"width\":1340,\"height\":754,\"caption\":\"Microsoft Teams EtherRAT Phishing Uses Fake IT Support Calls to Deliver Malware\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/microsoft-teams-etherrat-phishing\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Microsoft Teams EtherRAT Phishing Uses Fake IT Support Calls to Deliver Malware\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\",\"name\":\"Nora Blake\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"caption\":\"Nora Blake\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/nora-blake\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Microsoft Teams EtherRAT Phishing: Fake IT Support Scam","description":"Learn how the Microsoft Teams EtherRAT Phishing campaign works and how enterprises can reduce risk with Hexnode.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/microsoft-teams-etherrat-phishing\/","og_locale":"en_US","og_type":"article","og_title":"Microsoft Teams EtherRAT Phishing: Fake IT Support Scam","og_description":"Learn how the Microsoft Teams EtherRAT Phishing campaign works and how enterprises can reduce risk with Hexnode.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/microsoft-teams-etherrat-phishing\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-07-08T06:53:19+00:00","article_modified_time":"2026-08-19T06:57:52+00:00","og_image":[{"width":1340,"height":754,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Microsoft-Teams-EtherRAT-Phishing-Uses-Fake-IT-Support-Calls-to-Deliver-Malware.jpeg?format=webp","type":"image\/jpeg"}],"author":"Nora Blake","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Nora Blake","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/microsoft-teams-etherrat-phishing\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/microsoft-teams-etherrat-phishing\/"},"author":{"name":"Nora Blake","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d"},"headline":"Microsoft Teams EtherRAT Phishing Uses Fake IT Support Calls to Deliver Malware","datePublished":"2026-07-08T06:53:19+00:00","dateModified":"2026-08-19T06:57:52+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/microsoft-teams-etherrat-phishing\/"},"wordCount":1112,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/microsoft-teams-etherrat-phishing\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Microsoft-Teams-EtherRAT-Phishing-Uses-Fake-IT-Support-Calls-to-Deliver-Malware.jpeg?format=webp","articleSection":["Malware","Windows"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/microsoft-teams-etherrat-phishing\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/microsoft-teams-etherrat-phishing\/","url":"https:\/\/www.hexnode.com\/threat-watch\/microsoft-teams-etherrat-phishing\/","name":"Microsoft Teams EtherRAT Phishing: Fake IT Support Scam","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/microsoft-teams-etherrat-phishing\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/microsoft-teams-etherrat-phishing\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Microsoft-Teams-EtherRAT-Phishing-Uses-Fake-IT-Support-Calls-to-Deliver-Malware.jpeg?format=webp","datePublished":"2026-07-08T06:53:19+00:00","dateModified":"2026-08-19T06:57:52+00:00","description":"Learn how the Microsoft Teams EtherRAT Phishing campaign works and how enterprises can reduce risk with Hexnode.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/microsoft-teams-etherrat-phishing\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/microsoft-teams-etherrat-phishing\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/microsoft-teams-etherrat-phishing\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Microsoft-Teams-EtherRAT-Phishing-Uses-Fake-IT-Support-Calls-to-Deliver-Malware.jpeg?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Microsoft-Teams-EtherRAT-Phishing-Uses-Fake-IT-Support-Calls-to-Deliver-Malware.jpeg?format=webp","width":1340,"height":754,"caption":"Microsoft Teams EtherRAT Phishing Uses Fake IT Support Calls to Deliver Malware"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/microsoft-teams-etherrat-phishing\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Microsoft Teams EtherRAT Phishing Uses Fake IT Support Calls to Deliver Malware"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d","name":"Nora Blake","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","caption":"Nora Blake"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/nora-blake\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/951","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=951"}],"version-history":[{"count":2,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/951\/revisions"}],"predecessor-version":[{"id":958,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/951\/revisions\/958"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/956"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=951"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=951"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}