New malware targets Microsoft Teams users by posing as your company’s IT helpdesk


  • Expel researchers warn of SynkLoader backdoor spread via fake IT help desk Teams messages
  • Malware modules include PhishLocker (fake login screen harvesting OS passwords) and Interactive Shell for remote control
  • Defenses: distrust unsolicited Teams DMs, verify with IT before installing apps, and train staff against social engineering

For roughly a month now, cybercriminals have been targeting organizations with a new backdoor malware called SynkLoader.

According to security researchers Expel, the attack starts with social engineering. Victims would get a Microsoft Teams message from a person claiming to be from the company’s IT help desk. They would tell the victim their computer is having an issue, and that they need to install a “PowerShell Cleaner”. This fake program is nothing more than a malicious framework, hosted on Microsoft Azure to increase its trustworthiness.

Source link

spot_img
spot_img

Leave a reply

Please enter your comment!
Please enter your name here