New malware targets Microsoft Teams users by posing as your company's IT helpdesk
- Expel researchers warn of SynkLoader backdoor spread via fake IT help desk Teams messages
- Malware modules include PhishLocker (fake login screen harvesting OS passwords) and Interactive Shell for remote control
- Defenses: distrust unsolicited Teams DMs, verify with IT before installing apps, and train staff against social engineering
For roughly a month now, cybercriminals have been targeting organizations with a new backdoor malware called SynkLoader.
According to security researchers Expel, the attack starts with social engineering. Victims would get a Microsoft Teams message from a person claiming to be from the company’s IT help desk. They would tell the victim their computer is having an issue, and that they need to install a “PowerShell Cleaner”. This fake program is nothing more than a malicious framework, hosted on Microsoft Azure to increase its trustworthiness.
The malwareitself comes with a number of different modules, giving the attacker a range of features, from...
Copyright of this story solely belongs to techradar.com. To see the full text click HERE