Teams Helpdesk Scam Spreads SynkLoader Backdoor
Cybercriminals are using fake IT helpdesk messages on Microsoft Teams to deliver a new backdoor malware, researchers warn.
For roughly a month now, cybercriminals have been targeting organizations with a new backdoor malware called SynkLoader. According to security researchers Expel, the attack begins with a social engineering trick: victims receive a Microsoft Teams message from someone claiming to be from the company's IT help desk. The message tells the victim their computer is having an issue and that they need to install a “PowerShell Cleaner” — a fake program that is actually a malicious framework, hosted on Microsoft Azure to boost its credibility.
How the Attack Works
The attack chain starts with a convincing Teams direct message. Once the victim installs the fake cleaner, the malware establishes a foothold on the system. The malware itself comes with a range of modules that give attackers a variety of capabilities, from harvesting system information to creating a reverse proxy.
Two particularly worrying modules are called PhishLocker and Interactive Shell. The former creates a convincing, yet fake, Windows lock screen that can harvest the user's OS login password. The latter allows threat actors to remotely execute PowerShell commands and receive the output, essentially granting them full control over the infected device.
PhishLocker: A Fake Lock Screen
PhishLocker is designed to trick users into entering their Windows login credentials on a screen that looks identical to the legitimate one. BleepingComputer argues that with this password, attackers could “access corporate environments from the infected device, bypassing IP allow-list restrictions.”
Those with a sharper eye might spot the ruse, as a simple Alt + Tab shows that the login screen is nothing more than a “full-screen borderless GUI application.”
Interactive Shell: Full Control
The Interactive Shell module is equally dangerous. It enables remote execution of PowerShell commands, with the output sent back to the attacker. This gives the attacker essentially unrestricted control over the compromised machine, allowing them to move laterally, exfiltrate data, or deploy additional payloads.
“Access corporate environments from the infected device, bypassing IP allow-list restrictions.”
— BleepingComputer
Indicators of Compromise
The full list of Indicators of Compromise (IoC) can be found on this link. Organizations should review this list to check if they have been compromised.
Defending Against the Attack
To defend against these types of attacks, target companies should instruct their employees not to trust unsolicited Teams messages at face value, and not to install any applications without double-checking (calling) with their IT department first.
Alongside phone calls, Microsoft Teams is one of the most-used channels for initial contact and compromise. Also, employees remain the weakest link in every company's cybersecurity chain, unwillingly granting attackers access or sharing login credentials.
Why This Matters
This attack highlights a persistent threat: social engineering via collaboration tools is a low-cost, high-reward tactic for cybercriminals. The use of Microsoft Azure for hosting the malicious framework adds a layer of trust that can fool even cautious users. Businesses must treat unsolicited messages requesting software installation with suspicion, and invest in employee training to spot these ruses. The stakes are high, as a single compromised password could lead to a full network takeover.
Continue Reading
Notion, PDFs, and PaaS: Token Theft's New Shape
Threat actor Doubloon Dredger exploits Notion and device codes to steal authentication tokens, researchers say.
Venezuelan Gets Record Federal ATM Sentence
Juan Manuel Gouveia-Aguilera sentenced to 96 months for ATM jackpotting, with DOJ citing $3.5 million in losses.
Agent Tesla Variant Counters Detection With Emoji
New Agent Tesla v4 infostealer uses emoji obfuscation to evade detection and target finance departments.