🚨 Fake "IT Help Desk" on Microsoft Teams Is Pushing New SynkLoader Malware
Saturday, 22 August 2026
Security researchers at Expel have discovered a brand-new malware family called SynkLoader, and it's being delivered through one of the most trusted tools in the workplace: Microsoft Teams.
The attack is simple and effective. A message pops up in Teams from someone claiming to be your company's IT help desk, telling you to install a "PowerShell Cleaner" tool to fix a problem. The download looks trustworthy because it's hosted in Microsoft Azure. But the file is malware — and once installed, it can steal your password, spy on your screen, and open a backdoor into your company's network.
How the scam works
- A Teams message arrives from "IT support" — the name and picture look right, because attackers impersonate the target company's own help desk team.
- You're told to install a "PowerShell Cleaner" — a
.MSIinstaller file hosted in Microsoft Azure, which makes it look legitimate. - The installer runs silently. It unpacks a PowerShell script (
cleaner.ps1) and a ZIP archive packed with a Python framework, a malicious Python script, precompiled libraries, and fake Microsoft runtime files. - The malware reports home. Depending on what it finds on your computer, the attackers choose which tools (modules) to activate — from stealing your password to taking over your screen.
The malware first appeared around 28 July 2026, and researchers believe it's likely linked to ransomware operations because it's designed to map out how big a company's network is before attackers strike.
What SynkLoader can do
Expel's researchers (including well-known security expert Marcus Hutchins) set up a fake victim computer to watch the malware in action. They found several dangerous modules:
- Fake lock screen ("PhishLocker") — A convincing copy of the Windows login screen that captures your password when you type it.
- Screen takeover ("StreamMaster") — Streams your desktop and lets attackers move your mouse and type on your keyboard.
- Remote shell — Lets attackers run commands on your computer from anywhere.
- Traffic redirector — Turns your computer into a tunnel into your company's internal network.
- System profiler — Maps out your computer, accounts, and company network to plan the next stage.
- Persistence — Sets up a scheduled task so the malware relaunches every time you log in and daily at 10 a.m.
The sneaky fake lock screen
The most worrying part is the fake Windows lock screen. It looks almost identical to the real thing — but there's a giveaway: press Alt+Tab and your real open windows appear on top of it. A genuine Windows lock screen never does that. You can also press Ctrl+Alt+Delete — if the real Windows security screen doesn't appear, the lock screen is fake.
What this means for UK families and workers
Remote and hybrid working means more of us rely on Teams, Slack, and email to talk to colleagues — and criminals know it. Impersonating IT support is one of the fastest-growing tricks of 2026, because most people will click "install" when they think their own IT team asked them to.
The golden rule: never install software that someone messages you out of the blue — even if they claim to be from your own company's IT team.
Your family & workplace safety checklist
- Verify IT requests independently. If someone on Teams or email asks you to install software, contact your IT department through a known number or in person first. Never reply to the message itself.
- Never install unsolicited
.MSI,.EXEor.ZIPfiles. Legitimate IT teams don't send installers over chat without warning. When in doubt, ask. - Check unexpected lock screens. If a lock screen appears that you didn't trigger, press Alt+Tab (real windows should show) or Ctrl+Alt+Delete (the real security screen should appear). If something seems off, don't type your password.
- Use strong passwords and multi-factor authentication (MFA). Even if malware grabs your password, MFA can stop attackers from getting in. Never approve MFA prompts you didn't start.
- Keep your computer updated. Updated systems and antivirus with real-time protection make it harder for malware like this to run.
- Report it. If you think you've installed something suspicious, tell your IT team immediately, disconnect from the network, and report to Action Fraud at actionfraud.police.uk or on 0300 123 2040.
- At home, the same rules apply. Scammers impersonate banks, broadband providers, and even family members. Never install "support" software for someone who called or messaged you first.
The bottom line
Your IT help desk will never message you out of nowhere and ask you to install a "cleaner" tool. When an urgent Teams message tells you to click and install — slow down, close the chat, and verify through a trusted channel. That one pause is all it takes to stop SynkLoader in its tracks.
— CyberAware UK · 🐾 GUARDED BY BULLY — DIGITAL THREAT RESPONSE UNIT
