New malware targets Microsoft Teams users by posing as your company's IT helpdesk
Date:
Mon, 24 Aug 2026 17:15:00 +0000
Description:
Victims are being told to install a fake cleaner software which is nothing more than a backdoor framework.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Expel researchers warn of SynkLoader backdoor spread via fake IT help desk Teams messages Malware modules include PhishLocker (fake login screen harvesting OS passwords) and Interactive Shell for remote control Defenses: distrust unsolicited Teams
DMs, verify with IT before installing apps, and train staff against social engineering For roughly a month now, cybercriminals have been targeting organizations with a new backdoor malware called SynkLoader.
According to security researchers Expel, the attack starts with social engineering. Victims would get a Microsoft Teams message from a person claiming to be from the companys IT help desk. They would tell the victim their computer is having an issue, and that they need to install a PowerShell Cleaner. This fake program is nothing more than a malicious framework, hosted on Microsoft Azure to increase its trustworthiness. The malware itself comes with a number of different modules, giving the attacker a range of features, from harvesting system information, to creating a reverse proxy. Two particularly worrying modules are called PhishLocker and Interactive Shell. The former creates a convincing, yet fake, Windows lock screen, which can harvest the users OS login password. Latest Videos From TechRadar Watch full video here: This is not SickKids' first attack BleepingComputer argues that with this password the attackers could access corporate environments from the infected device, bypassing IP allow-list restrictions. Those with a sharper eye might spot the ruse, as a simple Alt + Tab shows that the login screen is nothing more than a full-screen borderless GUI application.
The other module - Interactive Shell, allows threat actors to remotely
execute PowerShell commands and receive the output, which essentially grants them full control over the infected device. You may like Microsoft login
pages are being abused as hackers try and lure in unlucky victims The enemy within: how to stop a simple Teams message taking down your business Hackers use fake Adobe and Zoom updates to load malware onto victim devices
The full list of Indicators of Compromise (IoC) can be found on this link .
To defend against these types of attacks, target companies should instruct their employees not to trust unsolicited Teams messages at face value, and
not to install any applications without double-checking (calling) with their IT department first.
Alongside phone calls, Microsoft Teams is one of the most-used channels for initial contact and compromise. Also, employees remain the weakest link in every companys cybersecurity chain, unwillingly granting attackers access or sharing login credentials. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features
and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.
Via BleepingComputer The best antivirus for all budgets Our top picks, based on real-world testing and comparisons
Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/new-malware-targets-microsoft-teams-use rs-by-posing-as-your-companys-it-helpdesk
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)