Microsoft Teams Helpdesk Scam Is Back — New SynkLoader Campaign Targets Corporate Users
- The Mess: A newer Microsoft Teams-based campaign is using fake IT helpdesk employees to convince corporate users to install a malicious program disguised as a legitimate “PowerShell Cleaner” utility. The malware, tracked as SynkLoader, can steal credentials and provide attackers with remote access to compromised systems. The campaign was first reported in August 2026 and is designed for deeper network compromise rather than simple credential theft.
This one caught my attention because it’s a newer development of a technique we’ve already seen becoming increasingly popular.
The attacker doesn’t need a vulnerability.
They don’t need to defeat Microsoft 365 security.
They don’t need to brute-force a password.
They simply pretend to be:
Your IT department.
And that’s enough to get the victim to execute the attack themselves.
The Attack Starts With Microsoft Teams
The attackers contact employees through Microsoft Teams while pretending to be internal IT support.
The scenario is deliberately believable.
The victim is told that something is wrong with their computer or mailbox and that IT needs to install a utility to fix it.
The victim is then directed toward a program presented as:
PowerShell Cleaner
It sounds technical.
It sounds legitimate.
And most importantly, it sounds like something an IT administrator might actually ask an employee to install.
But the program is malicious.
The campaign has been active since at least late July, with researchers observing malicious components being compiled around July 28, 2026.
SynkLoader Is More Than a Password Stealer
This is where the story becomes considerably more serious.
SynkLoader isn’t designed merely to grab one password and disappear.
The malware contains multiple capabilities that can help attackers maintain access and move deeper into corporate environments.
Reported functionality includes:
- credential theft;
- remote command execution;
- reverse-proxy functionality;
- VNC-style remote access;
- system reconnaissance;
- Active Directory profiling.
One component called PhishLocker can present a fake Windows lock screen designed to capture credentials.
Another component provides an interactive shell.
That potentially gives the attacker direct control over the compromised machine.
So the real attack chain looks more like:
Teams → fake IT → malicious utility → credentials → remote access → internal network.
That’s much worse than ordinary phishing.
Why Teams Is Such a Good Attack Platform
Employees have been trained for years to be suspicious of strange emails.
They look for:
fake domains.
bad spelling.
suspicious attachments.
unexpected links.
But what happens when the message arrives inside a platform people use every day?
Microsoft Teams.
The employee already trusts the application.
They already use it to communicate with colleagues.
They expect IT personnel to contact them there.
And that’s exactly what attackers are exploiting.
Security researchers have warned that collaboration applications are increasingly becoming an important phishing channel. Palo Alto Networks reported that phishing alerts involving collaboration tools represented 42% of all phishing alerts during the first four months of 2026, up from 30% in the preceding four months.
That’s a significant shift.
This Isn’t the Same Campaign as UNC6692
We’ve already discussed UNC6692, which used a similar Teams helpdesk impersonation technique.
That campaign started by flooding a victim’s inbox with spam and then approaching the victim through Teams pretending to be IT support.
The victim was directed to a fake “Mailbox Repair Utility” that eventually deployed the SNOW malware toolkit. Mandiant documented capabilities including credential theft, lateral movement and data exfiltration.
The important point is that the technique is spreading beyond one threat actor.
The basic formula works:
annoy the employee → create urgency → appear as IT → offer a solution → get the employee to run software.
That’s why we should be paying attention to the newer SynkLoader campaign.
The attackers are refining a proven social-engineering playbook.
No Exploit Required
This is perhaps the most frustrating aspect for defenders.
There doesn’t have to be a CVE.
There doesn’t have to be an unpatched Windows server.
There doesn’t have to be an exposed database.
The attack can work against a fully patched workstation.
All the attacker needs is:
a believable story + a Teams account + a cooperative victim.
That’s why traditional vulnerability management alone can’t stop this type of campaign.
Your servers can be perfectly patched.
Your firewall can be correctly configured.
Your EDR can be running.
And an employee can still say:
“Sure, I’ll install the tool IT sent me.”
Game over.
The Attackers Want the Corporate Network
The real objective isn’t necessarily the employee’s PC.
It’s what comes next.
Once the attacker has credentials and remote access, they can start looking for:
domain controllers.
file servers.
backup systems.
VPN infrastructure.
cloud credentials.
administrator accounts.
sensitive corporate data.
This is why helpdesk impersonation campaigns increasingly resemble the opening stage of ransomware attacks.
The initial access is social engineering.
The later stages are traditional enterprise intrusion.
And if the attackers reach privileged accounts, the original Teams conversation may become almost irrelevant.
The Fix
The best defense isn’t simply telling employees:
“Don’t trust Teams.”
That’s unrealistic.
Instead, organizations should establish a strict IT verification procedure.
For example:
IT should never ask employees to install remote-access software through an unsolicited Teams message.
If someone claiming to be IT contacts an employee:
close the chat.
call the official helpdesk number.
open a ticket through the normal IT portal.
verify the identity independently.
This destroys one of the attacker’s biggest advantages:
trust.
Organizations should also restrict external Teams communication where practical and monitor unusual external chats.
Palo Alto Networks specifically recommends tightening external collaboration controls and extending phishing-awareness training beyond email to Teams and other collaboration platforms.
Administrators Should Also Hunt for RMM Abuse
The broader Teams-helpdesk playbook frequently involves legitimate remote administration tools.
That’s another challenge.
An attacker using a legitimate RMM product doesn’t necessarily trigger the same alerts as a traditional malware executable.
So defenders should monitor:
- unexpected Quick Assist usage;
- unauthorized RMM installations;
- unusual remote-support sessions;
- PowerShell execution following Teams activity;
- suspicious browser extensions;
- new local administrator accounts;
- unusual outbound connections;
- authentication anomalies after helpdesk interactions.
The question shouldn’t simply be:
“Is this malware?”
It should also be:
“Why is this legitimate administration tool suddenly being used by this employee?”
Bugstoday Opinion
This is exactly the kind of attack I expect to become more common.
The traditional phishing email is becoming less interesting.
Attackers are moving toward trusted communication platforms.
Microsoft Teams.
Slack.
Zoom.
Google Workspace.
Internal chat.
The attacker’s objective is simple:
get the victim to believe that the attacker belongs there.
Once that happens, technical security controls become much harder to rely on.
And that’s why I like this story for Bugstoday.
It’s not another:
“Critical vulnerability allows remote code execution.”
It’s a completely different category of threat.
The employee becomes the exploit.
The attacker doesn’t exploit a software vulnerability.
They exploit trust.
Bugstoday verdict: if somebody suddenly contacts you through Microsoft Teams claiming to be IT and asks you to install a “security tool,” don’t trust the Teams identity. Close the conversation and contact your real IT department through a channel you already know. In this campaign, the fake helpdesk isn’t trying to fix your computer — it’s trying to take it over.




