New malware targets Microsoft Teams users by posing as your company’s IT helpdesk

New malware targets Microsoft Teams users by posing as your company’s IT helpdesk

By Sead Fadilpašić
Publication Date: 2026-08-24 17:15:00


  • Expel researchers warn of SynkLoader backdoor spread via fake IT help desk Teams messages
  • Malware modules include PhishLocker (fake login screen harvesting OS passwords) and Interactive Shell for remote control
  • Defenses: distrust unsolicited Teams DMs, verify with IT before installing apps, and train staff against social engineering

For roughly a month now, cybercriminals have been targeting organizations with a new backdoor malware called SynkLoader.

According to security researchers Expel, the attack starts with social engineering. Victims would get a Microsoft Teams message from a person claiming to be from the company’s IT help desk. They would tell the victim their computer is having an issue, and that they need to install a “PowerShell Cleaner”. This fake program is nothing more than a malicious framework, hosted on Microsoft Azure to increase its trustworthiness.