Filed under: Cybersecurity · Social Engineering · July 2026

What happened

Security researchers at Palo Alto Networks’ Unit 42 uncovered an active campaign in which criminals pose as your own IT support over Microsoft Teams. It starts with a phishing email — often an “Employee Survey” with a PDF attached — followed minutes later by a Teams voice call from an outside account claiming to be a “System Administrator.” The caller talks the employee into installing a legitimate remote-control tool like AnyDesk or HopToDesk, then uses that access to plant malware called EtherRAT that hands the attacker full control of the computer. This is happening in the wild right now, and researchers found the crooks are already on their ninth version of the installer.

Why it matters to your business

For a Phoenix small business, Teams and Microsoft 365 are everyday tools, and a friendly “IT is calling to fix something” feels completely normal — especially when there’s no in-house IT desk to check against. One employee granting remote access gives a stranger the keys to that machine: saved passwords, email, QuickBooks, client files, and a foothold to spread across your network. Because AnyDesk and HopToDesk are legitimate, widely-used programs, your antivirus usually won’t flag the initial break-in. The endgame is data theft, wire-transfer fraud, or ransomware.

What to do this week

Set one firm rule with your team: real IT never cold-calls to install software or take remote control — if someone does, hang up and call back on a number you already trust. In Teams, limit who can reach your staff from outside: open the Teams admin center (admin.teams.microsoft.com) → Users → External access, and block or tightly restrict unknown external domains and unmanaged Teams accounts. Make sure remote-control apps like AnyDesk, HopToDesk, TeamViewer, and Windows Quick Assist are only installed and used by your actual IT provider, and remove any your team doesn’t recognize. Finally, treat unexpected “Employee Survey” emails with PDF attachments as suspicious and report them.

The bigger picture

Attackers have shifted from breaking in to being invited in — the fastest route onto your network is now a convincing phone call, not a software flaw. Teaching your team to pause and verify before granting access is the control that stops this cold. Phishing Attacks: Why SMBs Are Prime Targets and How to Fight Back

Want help locking down Teams and remote-access tools before a fake “IT” call gets through? Book a free consult — https://micro1tech.com/contact/