Fake IT Support Calls on Microsoft Teams Push EtherRAT — Node.js RAT Using EtherHiding (Ethereum Smart Contract C2), Linked to React2Shell (CVE-2025-55182) Exploitation Chain — Threadlinqs Intelligence
As of 2026-07-06, Fake IT Support Calls on Microsoft Teams Push EtherRAT — Node.js RAT Using EtherHiding (Ethereum Smart Contract C2), Linked to React2Shell (CVE-2025-55182) Exploitation Chain is a high-severity malware threat attributed to Unattributed intrusion set leveraging EtherRAT (North Korea (DPRK) — suspected via TTP/tooling overlap; not confirmed for this specific Teams-vishing intrusion chain), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 41 indicators of compromise.
Threat ID: TL-2026-1141 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Unattributed intrusion set leveraging EtherRAT · North Korea (DPRK) — suspected via TTP/tooling overlap; not confirmed for this specific Teams-vishing intrusion chain · FINANCIAL
Threat actors impersonate IT/System Administrator staff via external Microsoft Teams accounts (e.g. helpdesk@Progressive936.onmicrosoft.com) and an 'Employee Survey' phishing lure to socially engineer
This threat documents an active social-engineering-to-malware campaign, first reported by Palo Alto Networks Unit 42 (GitHub report dated 2026-06-28, syndicated by BleepingComputer on 2026-07-06), in which attackers impersonate corporate IT/helpdesk staff to obtain hands-on-keyboard access to victim machines and deploy the EtherRAT remote access trojan. The intrusion begins with a phishing email carrying an 'Employee Survey' PDF lure, followed by a voice call or chat initiated from an external Microsoft Teams / Entra ID tenant account (helpdesk@Progressive936.onmicrosoft.com) impersonating a System Administrator. This mirrors a broader, well-documented 2026 trend of cross-tenant Teams helpdesk impersonation abused by multiple clusters (Microsoft's 'Help on the line' and cross-tenant helpdesk playbook advisories, Mandiant's UNC6692/SNOW malware campaign, and MuddyWater's false-flag ransomware Teams operation), all of which exploit Teams' default external-collaboration settings and use email bombing or urgency lures to justify unsolicited IT contact.
Once trust is established, the victim is walked through installing legitimate remote-access software (HopToDesk, then AnyDesk) via Teams screen-sharing, giving the attacker persistent remote control. The attacker then delivers a malicious MSI installer (observed as v1.msi through v9.msi in an open directory on camorreado.click) that acts as a loader: it silently drops a portable Node.js runtime, decrypts obfuscated JavaScript payloads, and launches EtherRAT.
EtherRAT is a cross-platform, Node.js-based backdoor whose defining feature is 'EtherHiding' — rather than hardcoding a C2 address that defenders can block or law enforcement can seize, the malware queries public Ethereum (and in related campaigns, BNB Smart Chain) RPC providers (e.g., 1rpc.io) to read the current C2 URL from an on-chain smart contract (observed contracts include 0xe26c57b7fa8de030238b0a71b3d063397ac127d3, 0xdf0b529043ef7a2bb9111bad26de624a326bacf9, and 0x5953f27F044779a3AFCd2BF56a4B712583Dd2E4e). Operators rotate infrastructure cheaply by issuing on-chain setString-style updates, and observed follow-on C2 destinations include TryCloudflare tunnels. Once connected, EtherRAT disguises beacon traffic as ordinary CDN requests (random hex paths, UUIDs, .ico/.png/.css extensions), persists via a 12-character randomized-hex Registry Run key executed headlessly through conhost.exe, self-modifies by having the C2 return freshly obfuscated source on each check-in, and provides remote command execution, file manipulation, OS/cloud fingerprinting, and theft of cryptocurrency wallets and cloud credentials. It also contains CIS-region language-based self-destruction logic consistent with DPRK-affiliated tooling.
Sysdig and multiple independent researchers (eSentire TRU, GBHackers, Infosecurity Magazine, cybersecuritynews) assess that EtherRAT and EtherHiding show significant TTP overlap with the DPRK-linked 'Contagious Interview' cluster tracked by Google as UNC5342 (aka CL-STA-0240, DeceptiveDevelopment, DEV#POPPER, Famous Chollima, Gwisin Gang, Tenacious Pungsan, Void Dokkaebi), which has used EtherHiding since February 2025 to serve JADESNOW/INVISIBLEFERRET payloads from BNB Smart Chain and Ethereum contracts in fake job-interview lures. However, EtherRAT is also observed operating as a malware-as-a-service capability used by other, apparently financially-motivated actors: The DFIR Report documented an April 2026 intrusion in which a malicious MSI masquerading as Sysinternals 'RAMMap' deployed EtherRAT, which was chained into the 'TukTuk' backdoor (DLL-sideloaded via trojanized Greenshot/SyncTrayzor/DocFX/Cake binaries, using ClickHouse Cloud, Supabase, Ably, Dropbox, GitHub Issues, and an Arweave-blockchain-hosted config as C2/fallback channels) and ultimately domain-wide 'Gentleman' ransomware deployment via a malicious Group Policy Object staged through SYSVOL/NETLOGON scheduled tasks, following extensive AD/domain-
Target sectors: retail, financial services, health, software, business services
Target regions: North America, Europe, Asia-Pacific
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 41 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, CVE-2025-55182, T1598, T1583, T1608, T1587, T1566, T1566, T1199, T1204, T1059, T1053