Fake IT Helpdesk Calls on Microsoft Teams Are Planting EtherRAT on Company PCs

Attackers pose as internal support staff over Teams voice calls, then walk employees through installing remote-access tools that drop a Node.js trojan.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 4 min read
Illustration: a modern open-plan office desk at dusk
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Palo Alto Networks' Unit 42 has documented an active campaign that uses phishing emails followed by Microsoft Teams voice calls from a fake 'System Administrator' to install EtherRAT malware.
  • The attacker calls from an external Microsoft 365 tenant, helpdesk@Progressive936.onmicrosoft[.]com, and Teams labels the session 'External unfamiliar'.
  • Victims are walked through installing HopToDesk and AnyDesk, after which a malicious MSI installer (v7.msi) is fetched from camorreado[.]click.
  • EtherRAT is a cross-platform remote access trojan written in Node.js that hides its command server address inside Ethereum smart contracts.
  • Unit 42 found an open directory holding installer versions v1 through v9, suggesting the campaign is still being built out.

A new attack chain, reported by BleepingComputer and detailed by Palo Alto Networks' Unit 42, shows criminals working the phones as well as the inbox: they call employees on Microsoft Teams and pretend to be the IT helpdesk. The goal is straightforward. Get remote control of the computer, then install malware.

How does the scam actually unfold?

It starts with a phishing email, a fake message designed to trick the reader. The lure is an 'Employee Survey' with a PDF attached. Shortly after the victim opens the document, their Teams rings. The caller claims to be a 'System Administrator' looking into a problem.

Unit 42 says the call comes from outside the company's own Microsoft 365 tenant, and Teams flags this with an 'External unfamiliar' label. Audit logs traced one attacker account to helpdesk@Progressive936.onmicrosoft[.]com.

The fake technician asks the employee to share their screen and grant remote control, both standard Teams features. The attacker then guides the victim through installing HopToDesk and AnyDesk, legitimate remote-support tools that IT departments use routinely. Because the software is real and signed, most antivirus products don't stop it.

With that access secured, the attacker downloads a Windows installer called v7.msi from camorreado[.]click. That installer pulls down a legitimate copy of Node.js, a programming runtime, then decrypts embedded payloads and launches EtherRAT.

What can EtherRAT do once it is inside?

EtherRAT is a remote access trojan that hands the attacker full control of the machine. It executes commands, manipulates files, steals data and persists across reboots.

Its distinguishing feature: instead of hard-coding the address of its command server, which defenders can block, it retrieves that address from an Ethereum smart contract on the public blockchain. The lookup can't be taken down by targeting a single server the attackers own.

Unit 42 notes the malware was previously deployed in state-sponsored attacks exploiting the React2Shell vulnerability before spreading to other criminal groups. The open directory of installers, v1 through v9, signals active development. We first covered EtherRAT on 6 July 2026; this campaign extends that picture.

Why does this keep working on Teams?

Because Teams is trusted inside the office in a way email no longer is. If your 'helpdesk' calls on the same platform your real helpdesk uses, most people pick up.

This isn't a novel playbook. A March campaign targeted financial and healthcare organisations using spam floods followed by Teams calls, Quick Assist sessions and the newly documented A0Backdoor. In April, Microsoft itself warned that external Teams accounts were being abused to impersonate support staff and pivot across corporate networks. Vishing as a corporate intrusion vector has been a recurring theme in our coverage since at least our June report on UNC3753, which blended phone social engineering with physical site visits.

Microsoft has responded. External callers and chats now carry visible warnings. Last week the company also introduced a Teams admin policy that automatically holds suspected third-party bots in the meeting lobby pending organiser approval, a change we covered when it was announced on 1 July.

Should you worry?

Yes, if your organisation hasn't locked down who can call employees from external tenants. The practical rule for staff is blunt: a real IT team won't cold-call you from an outside account and ask to take over your screen. Hang up and call the helpdesk on a number you already have.

© 2026 Threat Vectr