Hackers Pose as IT Help Desk in Microsoft Teams to Deliver SynkLoader and Steal Windows Passwords
Threat actors use attacker-controlled Microsoft 365 tenants to impersonate IT support in Teams external chats, tricking employees into installing the SynkLoader malware or granting remote access, and harvesting Windows credentials via a fake lock screen.
Threat actors are abusing Microsoft Teams external chats to impersonate IT help desk staff, tricking employees into installing malware or granting remote access and stealing Windows passwords through a fake lock screen. According to GBHackers (2026-09-21), corroborated by Cyber Security News (2026-09-22), the actors create Microsoft 365 tenants with display names like 'IT Service Desk' and contact victims via Teams external access, often using .onmicrosoft.com addresses and professional profile photos to appear legitimate. The attack relies on human trust rather than a software vulnerability. A documented campaign delivered a 'PowershellCleaner' MSI hosted on Azure Blob Storage that installs SynkLoader, a multi-language loader using Python, PowerShell, C#, and C++ with in-memory loading and scheduled-task persistence. Its PhishLocker module displays a fake full-screen Windows lock screen that reuses the device's real wallpaper to capture the plaintext password the user types, while a reverse-proxy feature routes attacker traffic through the compromised host to reach internal services. Cyber Security News adds that victims are pushed to run an MSI, open Quick Assist, or share a remote-access code; per GBHackers, related campaigns abused Quick Assist for interactive control and then used Rclone for reconnaissance, lateral movement, and exfiltration. Guidance — attributed to Microsoft by Cyber Security News — is to restrict Teams external access to trusted (allow-listed) domains and verify unexpected support requests through a known internal channel. The two reports do not conflict; Cyber Security News repeats the GBHackers account with fewer technical specifics.
- Attackers create Microsoft 365 tenants with display names like 'IT Service Desk', often using .onmicrosoft.com addresses and professional profile photos to appear legitimate (GBHackers, 2026-09-21).
- Initial contact occurs via Microsoft Teams external access/chat from attacker-controlled tenants; victims are pushed to run an MSI, open Quick Assist, or share a remote-access code (Cyber Security News, 2026-09-22).
- A documented campaign delivered a malicious 'PowershellCleaner' MSI hosted on Azure Blob Storage.
- The MSI installs SynkLoader, a multi-language loader using Python, PowerShell, C#, and C++, which runs largely in memory and persists via scheduled tasks.
- SynkLoader's PhishLocker module displays a fake full-screen Windows lock screen that reuses the device's real wallpaper to capture the plaintext password the user types.
- A reverse-proxy feature routes attacker traffic through the compromised host to reach internal services.
- Related campaigns abused Quick Assist for interactive control, then used Rclone for reconnaissance, lateral movement, and exfiltration.
- Recommended mitigations: allow-list trusted external Teams domains and verify unexpected IT support requests through a known internal channel; Cyber Security News attributes this guidance to Microsoft.
Coverage timelineoldest first · each row is one article
- · 5d agoHackers Abuse Microsoft Teams to Pose as IT Support and Steal Employee Passwords
GBHackers· 55
Threat actors impersonate IT support in Microsoft Teams chats to deliver SynkLoader malware and harvest Windows credentials via fake lock screens.
- · 5d agoHackers Impersonate IT Help Desk on Microsoft Teams to Steal Windows Passwords
Cyber Security News· 74
Attackers impersonate IT help desks in Microsoft Teams to deliver SynkLoader and steal Windows passwords.