In the current cybersecurity landscape, attackers are constantly refining their social engineering tactics to bypass technical defenses. A recent and particularly concerning example is the campaign using fake technical support calls via Microsoft Teams to deceive employees into handing over control of their computers. The strategy combines an initial phishing email, simulating a work survey, with a subsequent call from an external account posing as the IT department. During the conversation, the attacker convinces the victim to install legitimate remote administration tools like HopToDesk or AnyDesk, and from there downloads an MSI package that deploys the EtherRAT remote access trojan. This malware, developed in Node.js, is cross-platform (Windows, Linux, and macOS) and offers the attacker a wide range of capabilities: executing commands, stealing data, manipulating files, and maintaining persistence on the system. A distinctive feature is that it does not use a fixed command and control server address; instead, it dynamically obtains the address from a smart contract on the Ethereum blockchain, with a conventional backup domain. Unit 42 researchers have also identified a useful forensic artifact: during remote control sessions, Microsoft Teams generates files with names like CtrlVirtualCursorWin_*, which can alert security teams to an active intrusion. Additionally, an open repository has been discovered containing versions 1 through 9 of EtherRAT, with updates as recent as late June, indicating ongoing development by the operators.
This threat demonstrates how collaboration platforms, designed to increase productivity, become attack vectors when users lack proper training and tools. Identity spoofing through Teams calls exploits the trust employees place in internal communications. For organizations, this underscores the need to implement strict verification policies, such as requiring multi-factor authentication credentials and establishing official channels for support requests. But beyond awareness, effective defense requires robust technological solutions. At Q2BSTUDIO we offer cybersecurity and pentesting services that allow identifying vulnerabilities before attackers exploit them. Our teams conduct realistic penetration tests, simulating social engineering tactics like those described, to assess staff preparedness and infrastructure strength. Additionally, we complement this protection with custom software development and tailored applications that integrate security controls from the design phase, reducing the attack surface. Artificial intelligence also plays a key role: our AI solutions for businesses and AI agents can analyze behavioral patterns in Teams communications to detect anomalies indicating a potential attack. On the other hand, the continuous monitoring of AWS and Azure cloud service environments we implement allows auditing session logs and configurations, just as Unit 42 researchers use logs to track malicious activity. The combination of these capabilities, along with business intelligence and Power BI services to visualize security metrics, forms a comprehensive strategy that not only mitigates risks like EtherRAT but strengthens the entire defensive posture of the company.
The EtherRAT case is a reminder that technology advances for both defenders and attackers. While cybercriminals abuse legitimate tools and collaborative platforms, organizations must adopt a proactive approach. Staff training is essential, but without solid technological backing, any weak link can be exploited. In this context, betting on custom applications and tailored software that incorporate access controls and suspicious behavior detection becomes indispensable. Likewise, integrating artificial intelligence into cybersecurity processes allows automating incident response, reducing reaction time against social engineering campaigns. It is not just about reacting, but anticipating: with the right solutions, such as those we provide at Q2BSTUDIO, companies can turn their Teams environments and other platforms into digital fortresses, not entry doors. To delve deeper into how to protect your systems against this type of intrusion, we invite you to explore our capabilities in cross-platform application development, where security and usability converge to offer reliable environments.

.jpg)



