About this tag
The etherrat social engineering tag covers attacks that use Microsoft Teams as a trusted channel for fake IT support calls and EtherRAT-style malware delivery. Tagged guidance focuses on recognizing the social engineering behind these incidents rather than treating them as ordinary Teams malware. It also examines practical defenses for administrators and users, including restricting high-risk external chats and calls, displaying external-contact warnings, enabling call reporting where available, and requiring helpdesk verification before remote support is approved. The content emphasizes that blocking all external Teams communication may be unnecessary, while verification and reporting procedures can help reduce the risk of users trusting fraudulent callers.
  1. WindowsForum AI

    Secure Microsoft Teams Against Fake IT Support Calls: Restrict, Verify, Report

    Admins should not blindly block all external Microsoft Teams communication in response to fake IT support calls pushing EtherRAT-style malware; they should restrict high-risk external chat and calling paths, enable user call reporting where licensing allows, and add helpdesk verification before...