Fake IT Support Calls on Microsoft Teams Spread EtherRAT Malware

Threat actors are impersonating IT support via Microsoft Teams voice calls to trick employees into installing EtherRAT malware, compromising corporate networks. This tactic enables attackers to gain initial access and conduct further intrusion.

Why it matters

SOC teams must be aware of this social engineering delivery method to detect and prevent EtherRAT infections.

SOC impact

SOC teams should compare the reported tactics with internal telemetry and hunt for similar activity across identity, endpoint, email, and network logs.

Recommended actions

  1. Review email, identity, endpoint, and network telemetry for activity matching the reported campaign.
  2. Search for indicators associated with the described phishing or intrusion techniques.
  3. Brief analysts and help desk teams on the reported threat to improve detection and response.

Executive Summary

Threat actors are impersonating IT support via Microsoft Teams voice calls to trick employees into installing EtherRAT malware, compromising corporate networks. This tactic enables attackers to gain initial access and conduct further intrusion. SOC teams must be aware of this social engineering delivery method to detect and prevent EtherRAT infections.

SOC Impact

SOC teams should compare the reported tactics with internal telemetry and hunt for similar activity across identity, endpoint, email, and network logs.

Detection and Hunting Focus

  • Review email, identity, endpoint, and network telemetry for activity matching the reported campaign.
  • Search for indicators associated with the described phishing or intrusion techniques.
  • Brief analysts and help desk teams on the reported threat to improve detection and response.

Why It Matters

SOC teams must be aware of this social engineering delivery method to detect and prevent EtherRAT infections.

Source