New Malware Uses Fake IT Support on Microsoft Teams to Steal Passwords
A new malware called SynkLoader is spreading through Microsoft Teams messages where attackers pose as your company’s IT help desk.
The attack works like this: someone messages your staff on Teams pretending to be IT support and asks them to install a “PowerShell Cleaner” tool. The download is hosted on Microsoft Azure, so it looks legitimate. Once installed, SynkLoader locks the screen with a convincing fake Windows 11 login page and captures whatever password the user types in.
From there, it gets worse. The malware opens a backdoor into your network, lets attackers control the infected PC remotely, and — based on the toolset — is likely being used to set up ransomware attacks.
Why this matters for Australian businesses
Almost every SMB with Microsoft 365 uses Teams daily. Your staff are used to getting messages from IT — and that’s exactly what makes this effective. It exploits trust, not a technical flaw.
What to do right now
Tell your team: legitimate IT support will never cold-message you on Teams asking you to install software. If you get a message like that, call your IT provider on a known number to verify. We see this pattern regularly across our managed client base — attackers impersonating the help desk is one of the fastest-growing social engineering tactics hitting Australian businesses right now.
If you see an unexpected Windows lock screen, press Alt+Tab or Ctrl+Alt+Delete. A real lock screen won’t let you switch apps — a fake one will.
If your business needs help locking down Teams against external messages and phishing, talk to our cybersecurity team.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
