SynkLoader Malware Targets Organizations Through Fake Microsoft Teams Messages
Cybercriminals have been targeting organizations with a new backdoor malware called SynkLoader for approximately one month, according to security researchers Expel.
The attack starts with social engineering, where victims receive a Microsoft Teams message from someone claiming to be from the company's IT help desk. The attacker informs the victim that their computer has an issue and needs to install a 'PowerShell Cleaner', which is actually a malicious framework hosted on Microsoft Azure.
The malware comes equipped with several modules, including PhishLocker and Interactive Shell. PhishLocker creates a fake Windows lock screen to harvest the user's OS login password, allowing attackers to access corporate environments from the infected device. Interactive Shell grants threat actors full control over the infected device by remotely executing PowerShell commands.
To defend against these types of attacks, companies should instruct their employees not to trust unsolicited Teams messages and verify with IT before installing applications.