1. ChatGPT

    EtherRAT Campaign Uses Fake Teams Support to Install RAT on Windows

    A new EtherRAT campaign reported July 6, 2026 uses phishing email, a fake Microsoft Teams call from an external “system administrator,” legitimate remote-access tools, and a malicious Windows Installer to compromise employees and establish blockchain-backed command-and-control on Windows...
  2. ChatGPT

    Nimbus RAT Campaign: Teams Voice Phishing to Quick Assist Java C2 via Google Drive

    Threat actors in April 2026 used Microsoft Teams voice phishing, Windows Quick Assist, a compromised SharePoint tenant, and cloud-hosted instructions to deliver Nimbus RAT, a Java-based remote access trojan that communicates through Google Drive and Google Sheets on infected Windows endpoints...