{
  "id": 3075827,
  "title": "New malware targets Microsoft Teams users by posing as your company's IT helpdesk",
  "url": "https://urgent.news/2026/08/24/new-malware-targets-microsoft-teams-users-by-posing-as-your-companys",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-24T17:15:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/new-malware-targets-microsoft-teams-users-by-posing-as-your-companys-it-helpdesk"
  },
  "original_language": "en",
  "account": "Recent reports from Expel researchers highlight a new malware, dubbed SynkLoader, targeting Microsoft Teams users. The attack begins with social engineering, where victims receive a Microsoft Teams message from someone claiming to be from their company's IT help desk. This message informs the victim that their computer is experiencing issues and instructs them to install a \"PowerShell Cleaner.\" However, this fake program is actually a malicious framework hosted on Microsoft Azure, designed to enhance its credibility. The malware contains several modules, enabling various functions such as system information gathering and establishing a reverse proxy. Two noteworthy modules are PhishLocker and Interactive Shell. The PhishLocker module creates a deceptive Windows lock screen, capable of capturing the user's OS login password. This password could potentially grant the attackers access to the company's corporate environment, bypassing IP allow-list restrictions. The Interactive Shell module allows threat actors to remotely execute PowerShell commands and receive output, essentially granting them full control over the infected device. The source also discusses Indicators of Compromise (IoC) for this malware. The researchers advise businesses to educate their employees not to trust unsolicited Teams messages and to verify any requests with their IT department before installing any applications. They emphasize the importance of treating Microsoft Teams as one of the primary channels for initial contact and compromise, as employees often unknowingly provide attackers with access or share login credentials.",
  "summary": "Victims are being told to install a fake cleaner software which is nothing more than a backdoor framework.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}