Hackers Impersonate IT Help Desk on Microsoft Teams to Steal Windows Passwords
Attackers impersonate IT help desks in Microsoft Teams to deliver SynkLoader and steal Windows passwords.
Attackers are using Microsoft Teams external chats from Microsoft 365 tenants they control to impersonate IT help desks and trick employees into installing malware or approving remote access. One campaign delivered SynkLoader as a malicious MSI hosted on Azure storage; it can run largely in memory and persist through scheduled tasks. Its PhishLocker module displays a fake Windows lock screen that captures the password the user types. Microsoft recommends restricting Teams external access to trusted domains and verifying unexpected support requests through a known internal channel.