Unit 42 reports attackers posing as helpdesk staff on Microsoft Teams persuade employees to hand over remote control, then drop the EtherRAT trojan.