Field Analysis
The Admin Calls You: Cross-Tenant Teams Screen-Control to EtherRAT
A late-June 2026 intrusion pivoted from an email lure to an external Teams call posing as 'System Administrator,' drove the victim's desktop through Teams screen-control, and staged a Node.js-based EtherRAT that resolves its C2 from an Ethereum smart contract. The trusted channel is the tradecraft.
Read more:Unit 42 (Palo Alto Networks)GBHackers