A new backdoor is spreading through Microsoft Teams by posing as your own IT department.
Researchers at Expel say the malware, called SynkLoader, has been active for about a month. Attackers open with a direct Teams message claiming to be IT help desk staff, telling the target their computer is broken and that they need to install a "PowerShell Cleaner" tool to fix it. That tool is hosted on Microsoft Azure, which makes the link look far more legitimate than a random download. Once installed, SynkLoader can pull system information, open a reverse proxy, throw up a fake Windows lock screen to steal login passwords, or hand attackers a live PowerShell shell for full remote control.
A stolen OS password is more valuable than it sounds: it lets attackers log into corporate systems from a device that already looks trusted, sidestepping the IP allow-list rules that would normally flag an outside login. That turns a malware problem into an identity problem, since the intruder shows up looking like a normal employee rather than a piece of malicious code security tools would flag.
The fake lock screen is convincing until you hit Alt+Tab and discover it is just a borderless window pretending to be Windows - proof that most of these attacks still succeed the old-fashioned way, by getting someone to trust the wrong message.