Executive Summary
In July 2026, threat actors initiated a sophisticated phishing campaign targeting corporate employees by impersonating IT support staff via Microsoft Teams voice calls. The attack began with phishing emails containing malicious PDF attachments labeled as 'Employee Survey.' Shortly after opening the document, victims received Teams calls from external accounts posing as system administrators. Exploiting Teams' screen-sharing feature, attackers convinced employees to install legitimate remote-access tools like HopToDesk and AnyDesk. Subsequently, they deployed a malicious MSI installer that downloaded and executed EtherRAT, a cross-platform remote access trojan written in Node.js, granting full control over compromised systems. EtherRAT enables attackers to execute commands, manipulate files, steal data, and maintain persistence, utilizing Ethereum smart contracts to retrieve its command-and-control server, complicating disruption efforts. This campaign underscores the evolving tactics of cybercriminals leveraging trusted communication platforms to infiltrate corporate networks. Organizations must enhance their security awareness training, implement robust authentication measures, and monitor for unusual activities within collaboration tools to mitigate such threats.
Why This Matters Now
The increasing abuse of trusted communication platforms like Microsoft Teams for sophisticated phishing attacks highlights the urgent need for organizations to bolster their security protocols and employee training to prevent unauthorized access and data breaches.
Attack Path Analysis
The attack began with a phishing email containing a malicious PDF attachment, followed by a Microsoft Teams call from an external account impersonating IT support. The attacker convinced the victim to install legitimate remote-access tools, establishing remote control. They then downloaded and executed a malicious MSI installer, deploying EtherRAT malware. EtherRAT established command and control, allowing the attacker to execute commands and manipulate files. The malware facilitated data exfiltration and maintained persistence on the compromised system.
Kill Chain Progression
Initial Compromise
Description
The attacker sent a phishing email with a malicious PDF attachment, followed by a Microsoft Teams call impersonating IT support to gain the victim's trust.
Related CVEs
CVE-2025-55182
CVSS 10A critical remote code execution vulnerability in React Server Components and Next.js due to unsafe deserialization of untrusted data.
Affected Products:
React React Server Components – All versions prior to patch
Vercel Next.js – All versions prior to patch
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Spearphishing Attachment
Web Protocols
Malicious File
Remote Access Software
JavaScript
Ingress Tool Transfer
Valid Accounts
Mail Protocols
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – User Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
High-value targets for EtherRAT trojans via Microsoft Teams impersonation attacks, requiring enhanced egress security and zero trust segmentation for regulatory compliance.
Health Care / Life Sciences
Critical HIPAA compliance risks from remote access trojans targeting Teams infrastructure, necessitating encrypted traffic controls and threat detection capabilities.
Information Technology/IT
Primary attack vector exploiting IT support impersonation through Teams calls, demanding multicloud visibility and anomaly detection to prevent lateral movement.
Computer Software/Engineering
Node.js-based EtherRAT malware specifically threatens development environments using Teams collaboration, requiring Kubernetes security and inline IPS protection.
Sources
- Fake IT support calls on Microsoft Teams push EtherRAT malwarehttps://www.bleepingcomputer.com/news/security/fake-it-support-calls-on-microsoft-teams-push-etherrat-malware/Verified
- React2Shell (CVE-2025-55182): Critical React and Next.js RCE Now Weaponized by EtherRAT Malwarehttps://cybersecurefox.com/en/react2shell-cve-2025-55182-etherrat-nextjs-ethereum-c2/Verified
- EtherRAT Malware - Malware removal instructions (updated)https://www.pcrisk.com/removal-guides/35286-etherrat-malwareVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix Zero Trust CNSF may not prevent the initial phishing attack, it would likely limit the attacker's subsequent network access, reducing the potential for further exploitation.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation would likely restrict the attacker's ability to leverage elevated privileges to access sensitive systems, thereby limiting the scope of potential damage.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security would likely limit the attacker's ability to move laterally, reducing the risk of additional system compromises.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control would likely detect and restrict unauthorized command and control communications, limiting the attacker's ability to manage compromised systems.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement would likely limit the attacker's ability to exfiltrate data by controlling and monitoring outbound traffic.
Aviatrix Zero Trust CNSF would likely reduce the attacker's ability to leverage persistence for further malicious activities by limiting access to critical systems and data.
Impact at a Glance
Affected Business Functions
- IT Support Services
- Network Security Operations
- Employee Training Programs
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of sensitive corporate data and employee credentials.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to limit lateral movement within the network.
- • Enforce Egress Security & Policy Enforcement to control outbound traffic and prevent unauthorized data exfiltration.
- • Utilize Threat Detection & Anomaly Response to identify and respond to suspicious activities promptly.
- • Deploy Inline IPS (Suricata) to detect and prevent known exploit patterns and malicious payloads.
- • Enhance user training to recognize phishing attempts and social engineering tactics.



