Affected Systems

Organizations using Microsoft Teams for internal communications. All industries are potential targets. The campaign exploits user trust in voice-based IT support interactions rather than a technical vulnerability in Teams itself.

Exploitation Status

Active campaign confirmed. Threat actors are conducting live social engineering attacks via Microsoft Teams voice calls. This is an ongoing operational threat, not a theoretical vulnerability.

Business Impact

Successful attacks result in EtherRAT malware installation, granting attackers initial access to corporate networks. This enables lateral movement, data exfiltration, credential theft, and potential ransomware deployment. The social engineering vector bypasses technical controls and relies on user deception. High risk for organizations with remote workforces heavily dependent on Teams for IT support communications.

Urgency

🟠 Within 24 hours

Recommended Actions

  • Immediately brief IT support staff and end users on this active campaign; emphasize that legitimate IT will never request software installation via unsolicited Teams calls
  • Configure Microsoft Teams to restrict external calls or require approval for external communications if not business-critical
  • Implement out-of-band verification procedures: employees must confirm IT support requests through a separate channel (phone directory, ticketing system) before taking action
  • Monitor endpoint detection and response (EDR) tools for EtherRAT indicators of compromise and suspicious remote access tool installations following Teams voice activity
  • Review Teams call logs for unusual patterns, especially unsolicited inbound calls claiming to be IT support, and correlate with help desk tickets to identify unauthorized contact attempts