Breaking
Cyber CrimeDeveloping Story

Teams Helpdesk Scam Spreads SynkLoader Backdoor

Cybercriminals are using fake IT helpdesk messages on Microsoft Teams to deliver a new backdoor malware, researchers warn.

··2 hours ago·2 min read
Code is displayed on a computer screen
Photo by Rob Wingate on Unsplash

For roughly a month now, cybercriminals have been targeting organizations with a new backdoor malware called SynkLoader. According to security researchers Expel, the attack begins with a social engineering trick: victims receive a Microsoft Teams message from someone claiming to be from the company's IT help desk. The message tells the victim their computer is having an issue and that they need to install a “PowerShell Cleaner” — a fake program that is actually a malicious framework, hosted on Microsoft Azure to boost its credibility.

How the Attack Works

The attack chain starts with a convincing Teams direct message. Once the victim installs the fake cleaner, the malware establishes a foothold on the system. The malware itself comes with a range of modules that give attackers a variety of capabilities, from harvesting system information to creating a reverse proxy.

Two particularly worrying modules are called PhishLocker and Interactive Shell. The former creates a convincing, yet fake, Windows lock screen that can harvest the user's OS login password. The latter allows threat actors to remotely execute PowerShell commands and receive the output, essentially granting them full control over the infected device.

PhishLocker: A Fake Lock Screen

PhishLocker is designed to trick users into entering their Windows login credentials on a screen that looks identical to the legitimate one. BleepingComputer argues that with this password, attackers could “access corporate environments from the infected device, bypassing IP allow-list restrictions.”

Those with a sharper eye might spot the ruse, as a simple Alt + Tab shows that the login screen is nothing more than a “full-screen borderless GUI application.”

Interactive Shell: Full Control

The Interactive Shell module is equally dangerous. It enables remote execution of PowerShell commands, with the output sent back to the attacker. This gives the attacker essentially unrestricted control over the compromised machine, allowing them to move laterally, exfiltrate data, or deploy additional payloads.

“Access corporate environments from the infected device, bypassing IP allow-list restrictions.”

— BleepingComputer

Indicators of Compromise

The full list of Indicators of Compromise (IoC) can be found on this link. Organizations should review this list to check if they have been compromised.

Defending Against the Attack

To defend against these types of attacks, target companies should instruct their employees not to trust unsolicited Teams messages at face value, and not to install any applications without double-checking (calling) with their IT department first.

Alongside phone calls, Microsoft Teams is one of the most-used channels for initial contact and compromise. Also, employees remain the weakest link in every company's cybersecurity chain, unwillingly granting attackers access or sharing login credentials.

Why This Matters

This attack highlights a persistent threat: social engineering via collaboration tools is a low-cost, high-reward tactic for cybercriminals. The use of Microsoft Azure for hosting the malicious framework adds a layer of trust that can fool even cautious users. Businesses must treat unsolicited messages requesting software installation with suspicion, and invest in employee training to spot these ruses. The stakes are high, as a single compromised password could lead to a full network takeover.

#synkloader#malware#microsoft teams#phishing#expel#backdoor

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories