KOM CLOUDSERVICE
All Insights

Fake IT Help Desk on Teams Installs a Fake Windows Lock Screen

A new malware family called SynkLoader arrives as a Teams message from your IT help desk and steals the Windows password you type to unlock.

Someone messages your office manager on Teams. The display name says IT help desk. They say there’s a performance issue on her machine and send a cleanup tool. She runs it. An hour later her screen locks, she types her Windows password to get back in, and the password goes straight to a criminal.

That’s the short version of a campaign Bleeping Computer reported this week, based on research from Expel. The malware is new, it’s called SynkLoader, and the whole thing is built around one idea: people trust a Teams message more than an email.

What actually happens

The attacker starts a Teams chat impersonating the target company’s own help desk. Microsoft flagged this help-desk impersonation pattern earlier in the year as a growing part of multi-stage attacks, and this campaign is a clean example of it.

The victim is walked through installing a “PowerShell Cleaner” installer file (.MSI). Here’s the clever part: the file is hosted in Microsoft Azure. So the download URL looks like it belongs to Microsoft. Your web filter sees a Microsoft cloud domain. Your user sees a Microsoft cloud domain. Nobody blinks.

Once it runs, the installer drops a PowerShell script and a ZIP full of components: a Python runtime, a malicious Python script, and several DLL files disguised as Microsoft runtime libraries. Expel named it SynkLoader because it mixes Python, PowerShell, C#, and C++, sometimes three languages inside a single module. That mix is not a flex. It’s a way to slip past tools that only know how to look at one kind of file.

Then the attackers pick which modules to deploy based on what they find. Expel identified these by running a honeypot that pretended to be a victim:

  • System Profiler. Hostname, username, whether the account is an admin, running processes, services, domain details, and how many computers are in Active Directory. In other words: is this shop worth robbing, and how big is it.
  • Persistence. A randomly named scheduled task that relaunches the malware at every logon and again daily at 10 a.m.
  • PhishLocker. A convincing fake Windows lock screen that captures the password the user types to “unlock.”
  • TrafficRedirector. A reverse proxy so attackers can reach other machines on your internal network, or route their own traffic out through your office IP.
  • Interactive Shell. Remote command execution.
  • StreamMaster. Live screen streaming plus remote mouse and keyboard on the user’s active session.

Why the lock screen matters more than it sounds

Stealing a Windows password from a small office feels like a small win. It isn’t, and here’s why.

Combine that password with the tunneling module and the attackers can log in to your systems from the infected computer itself. That means traffic comes from your office, your IP address, your network. Any control you have that says “only allow sign-ins from our location” is now useless, because they are, technically, at your location.

It’s the same problem we’ve written about before with session theft: MFA can be on and attackers still get in, because they’re not fighting the login. They’re standing behind it.

One useful detail from Expel: the fake lock screen is just a full-screen borderless window. Hit Alt+Tab and you’ll see the real desktop and open apps sitting behind it. A real Windows lock screen does not do that. That’s a tell worth teaching your staff today, in one sentence, at your next huddle.

What actually stops this

The break-in point is not a software flaw. It’s a chat message. So the fixes are mostly about who can message you and what your users can install.

Lock down external Teams chat. By default, outside parties can start conversations with your staff. Restrict external access to a short list of domains you actually work with, or turn it off. Most small offices lose nothing.

Establish one way your help desk contacts people, and say it out loud. If your IT support never opens an unsolicited Teams chat asking someone to install something, then any chat that does is fake, full stop. Put that in writing. Repeat it quarterly.

Stop users from installing MSI files. Standard users should not be local administrators on their own machines. This single change turns a full compromise into a failed download for most of these campaigns.

Run endpoint detection that watches behavior, not file names. A scheduled task with a random name that launches a Python script at 10 a.m. every day is exactly the kind of thing endpoint detection we deploy for clients is supposed to flag, and antivirus alone usually won’t.

Reset the password, not just the machine. If a user ever typed credentials into something suspicious, reimaging the laptop doesn’t undo it. Reset the account password and revoke active sessions in Microsoft 365.

None of these are expensive. They’re settings and habits. The campaigns that beat small businesses almost always beat them on the settings, not the budget. If you’re not sure where you stand on external Teams access or local admin rights, that’s a fifteen minute conversation. Book a free 15-minute consult.

Talk to the person who'll actually run your IT.

Book a free 15-minute consult. No sales pitch from a stranger, just a straight conversation about what your business needs.

Book your free consult

Or call (732) 701-7012

Monthly agreements, not multi-year lock-ins  ·  No call centers, ever