💻
New SynkLoader backdoor malware targets Microsoft Teams users via fake IT helpdesk
💻 Technology

New SynkLoader backdoor malware targets Microsoft Teams users via fake IT helpdesk

Security researchers at Expel have warned of a new backdoor malware called SynkLoader, which has been targeting organisations for roughly a month. Attackers impersonate IT helpdesk staff via Microsoft Teams messages, tricking victims into installing a fake "PowerShell Cleaner" tool hosted on Microsoft Azure. The malware includes a PhishLocker module that harvests OS passwords via a fake login screen, plus an interactive shell for remote control. Organisations are advised to distrust unsolicited Teams DMs and verify IT requests before installing any software.

Comments

No comments yet