Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: synkloader (1 article)Clear

Teams help desk impersonation delivers SynkLoader and a fake lock screen

Researchers at Expel found a new malware toolkit, SynkLoader, spread through Microsoft Teams messages in which attackers pose as a company's IT help desk. Using their own Microsoft tenant and an onmicrosoft.com address for credibility, they talk an employee into installing a fake "PowerShell Cleaner" hosted on Microsoft's own Azure storage. Once installed, SynkLoader can load modules including a convincing full-screen fake Windows lock screen that captures the user's password, plus a reverse proxy, remote shell, and remote desktop control. Its focus on counting Active Directory systems suggests it is used by a ransomware group or access broker to size targets. The fake lock screen can be escaped with Alt+Tab or Ctrl+Alt+Delete.

Check
Tell staff to verify unsolicited IT-support messages in Teams through a known internal channel before installing anything, and hunt for unapproved MSI installs, new scheduled tasks, and in-memory PowerShell.
Affected
Organizations allowing external Teams messages, where an attacker impersonating IT support can deliver SynkLoader; it steals passwords via a fake lock screen and provides proxy, shell, and remote-desktop access toward likely ransomware.
Fix
Restrict or closely monitor external Teams communication, block untrusted MSI downloads and known command-and-control infrastructure, watch for suspicious scheduled tasks and Python or PowerShell activity, and train staff on help-desk impersonation lures.