New malware targets Microsoft Teams users by posing as your company's IT helpdesk
Victims are being told to install a fake cleaner software
- Expel researchers warn of SynkLoader backdoor spread via fake IT help desk Teams messages
- Malware modules include PhishLocker (fake login screen harvesting OS passwords) and Interactive Shell for remote control
- Defenses: distrust unsolicited Teams DMs, verify with IT before installing apps, and train staff against social engineering
For roughly a month now, cybercriminals have been targeting organizations with a new backdoor malware called SynkLoader.
According to security researchers Expel, the attack starts with social engineering. Victims would get a Microsoft Teams message from a person claiming to be from the company’s IT help desk. They would tell the victim their computer is having an issue, and that they need to install a “PowerShell Cleaner”. This fake program is nothing more than a malicious framework, hosted on Microsoft Azure to increase its trustworthiness.
The malware itself comes with a number of different modules, giving the attacker a range of features, from harvesting system information, to creating a reverse proxy. Two particularly worrying modules are called PhishLocker and Interactive Shell. The former creates a convincing, yet fake, Windows lock screen, which can harvest the user’s OS login password.
This is not SickKids' first attack
BleepingComputer argues that with this password the attackers could “access corporate environments from the infected device, bypassing IP allow-list restrictions”. Those with a sharper eye might spot the ruse, as a simple Alt + Tab shows that the login screen is nothing more than a “full-screen borderless GUI application”.
The other module - Interactive Shell, allows threat actors to remotely execute PowerShell commands and receive the output, which essentially grants them full control over the infected device.
The full list of Indicators of Compromise (IoC) can be found on this link. To defend against these types of attacks, target companies should instruct their employees not to trust unsolicited Teams messages at face value, and not to install any applications without double-checking (calling) with their IT department first.
Alongside phone calls, Microsoft Teams is one of the most-used channels for initial contact and compromise. Also, employees remain the weakest link in every company’s cybersecurity chain, unwillingly granting attackers access or sharing login credentials.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Via BleepingComputer
➡️ Read our full guide to the best antivirus
1. Best overall:
Bitdefender Total Security
2. Best for families:
Norton 360 with LifeLock
3. Best for mobile:
McAfee Mobile Security
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.
You must confirm your public display name before commenting
Please logout and then login again, you will then be prompted to enter your display name.