- Expel researchers warn of SynkLoader backdoor spread via fake IT help desk Teams messages
- Malware modules include PhishLocker (fake login screen harvesting OS passwords) and Interactive Shell for remote control
- Defenses: distrust unsolicited Teams DMs, verify with IT before installing apps, and train staff against social engineering
For roughly a month now, cybercriminals have been targeting organizations with a new backdoor malware called SynkLoader.