SynkLoader Mimic as IT Support Personnel Attacking Users Via Microsoft Teams
Brief
SynkLoader is using Microsoft Teams conversations to turn routine IT support requests into a route for malware delivery.
The campaign relies on impersonation rather than a software flaw, placing the decision to install a supposed fix directly in front of an employee.
Attackers contact targets through Teams messages and voice phishing, also called vishing, while posing as support personnel.
They persuade victims to download a fraudulent MSI installer called “PowerShell Cleaner,” making a familiar workplace channel part of the attack chain.
Analysts from ReliaQuest Threat Research identified SynkLoader as a hash-gated PowerShell loader. The threat is notable because it combines a convincing social approach with code designed to reveal little when researchers or automated tools inspect it.
