[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fb4gT7fn-fGOUKQ9STdxU8Kinb1lSpfVw12iOFn01o4k":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":26,"created_at":27,"published_at":28,"article":29,"tags":33,"podcasts":52},"fbe26dae-8aae-4b87-8bd4-dc7ecaf13ef7","fake-it-support-calls-on-microsoft-teams-deliver-etherrat-via-social-engineering","6dc89663-82c1-4ce3-b575-04251d1f1f53","Fake IT Support Calls on Microsoft Teams Deliver EtherRAT via Social Engineering","Threat actors are exploiting employee trust in IT support channels by impersonating helpdesk staff through Microsoft Teams voice calls, combining vishing with phishing emails to manipulate victims into installing malware. The use of legitimate remote access tools as an initial foothold makes detection difficult and lends credibility to the attacker's ruse. EtherRAT's use of Ethereum smart contracts for command-and-control (C2) is particularly dangerous because it allows attackers to blend malicious traffic with legitimate blockchain communications, evading traditional network-based detection. This attack highlights how social engineering remains one of the most effective and underestimated vectors for initial access into corporate environments.","**Immediate Actions:**\n- Issue a company-wide alert educating employees that IT support staff will never initiate unsolicited calls requesting remote access or software installation.\n- Restrict or require approval for installation of remote access tools (e.g., AnyDesk, TeamViewer) on corporate endpoints via application allowlisting.\n- Block or flag outbound connections to known Ethereum RPC endpoints and unusual blockchain-related domains at the network perimeter.\n\n**Long-Term Improvements:**\n- Implement a verified IT support request workflow (e.g., ticketing system) so employees can confirm the legitimacy of any inbound support interaction before granting access.\n- Enforce least-privilege principles and require multi-factor authentication before any remote session can be established on corporate systems.\n- Conduct regular vishing and phishing simulation exercises targeting help-desk impersonation scenarios to build employee resilience.\n\n**Detection Measures:**\n- Deploy endpoint detection and response (EDR) solutions capable of identifying Node.js-based loaders and anomalous process execution chains.\n- Monitor Microsoft Teams call logs and flag unsolicited external voice calls or guest account interactions reaching internal employees.\n- Establish behavioral baselines and alert on unexpected outbound traffic to blockchain networks or smart contract endpoints from corporate hosts.",[12,13,14,15,16,17,18,19,20,21,22,23,24,25],"CIS Control 3: Data Protection","CIS Control 5: Account Management","CIS Control 9: Email and Web Browser Protections","CIS Control 14: Security Awareness and Skills Training","CIS Control 16: Application Software Security","NIST SP 800-53 AT-2: Security Awareness Training","NIST SP 800-53 AC-17: Remote Access","NIST SP 800-53 SI-3: Malicious Code Protection","NIST SP 800-53 IR-6: Incident Reporting","NIST CSF DE.CM-1: Network Monitoring","MITRE ATT&CK T1566: Phishing","MITRE ATT&CK T1219: Remote Access Software","MITRE ATT&CK T1071: Application Layer Protocol (C2)","GDPR Article 32: Security of Processing","published","2026-07-06T22:21:17.37352+00:00","2026-07-06T22:21:17.235+00:00",{"id":7,"url":30,"slug":31,"title":32},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Ffake-it-support-calls-on-microsoft-teams-push-etherrat-malware\u002F","fake-it-support-calls-on-microsoft-teams-push-etherrat-malware-1bc1a1","Fake IT support calls on Microsoft Teams push EtherRAT malware",[34,40,46],{"id":35,"name":36,"slug":37,"description":38,"color":39},"182e11d5-57c4-444e-8ec8-4682ad60261b","Incident Response","incident-response","Slow detection, poor containment, missing playbooks","#14b8a6",{"id":41,"name":42,"slug":43,"description":44,"color":45},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":47,"name":48,"slug":49,"description":50,"color":51},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[]]