Hackers Abuse Microsoft Teams to Pose as IT Support and Steal Employee Passwords
Threat actors impersonate IT support in Microsoft Teams chats to deliver SynkLoader malware and harvest Windows credentials via fake lock screens.
Attackers create Microsoft 365 tenants with display names like 'IT Service Desk' and contact victims through Teams external access, often using .onmicrosoft.com addresses and professional profile photos to appear legitimate. A documented campaign delivered a 'PowershellCleaner' MSI from Azure Blob Storage that installs SynkLoader, a multi-language loader using Python, PowerShell, C#, and C++ with in-memory loading and scheduled-task persistence. Its PhishLocker module shows a fake full-screen lock screen reusing the device's real wallpaper to capture plaintext credentials, and a reverse proxy routes attacker traffic through the compromised host. Other campaigns abused Quick Assist for interactive control, then used Rclone for reconnaissance, lateral movement, and exfiltration.