Fake “IT support” calls on Microsoft Teams install malware

You get a Microsoft Teams call from “IT support”. Except it isn’t your IT. Unit 42 (Palo Alto Networks) documented an active campaign: first a phishing email with a decoy PDF, then a voice call from an external account posing as a system administrator.

The victim is convinced to grant remote control and install AnyDesk or HopToDesk. From there, the attackers deploy the EtherRAT trojan and take full control of the computer. Small firms without in-house IT are the ideal target — nobody can quickly verify who the “technician” really is.

What you can do

  • A rule for the whole team: we never install remote-access software at a caller’s request, whoever they claim to be.
  • Check the “External” label on Teams calls and chats — real IT does not call from another tenant.
  • If you don’t collaborate externally on Teams, restrict external access in the admin settings.

Sources

This article was generated with AI assistance.

Security rules for your team

← All news