CyberSecurityNews

Hackers Impersonate IT Help Desk on Microsoft Teams to Steal Windows Passwords


Hackers are abusing Microsoft Teams chats to impersonate IT help desk staff, trick employees into installing malware or granting remote access, and steal Windows passwords through a fake lock screen.

The attacks don’t require a software vulnerability they rely on an employee trusting a convincing message from what appears to be internal IT support.

Attackers start the campaign from Microsoft 365 tenants they control. They create display names such as “IT Service Desk” or “Help Desk,” then contact employees through Teams external chat.

Because Teams allows communication with external domains by default, attackers can reach users from another Microsoft 365 tenant if external access is enabled on both sides.

The message often claims that IT needs to fix a security issue, clean a device, resolve email problems, or install an urgent update. The attacker then asks the employee to download a file, approve screen control, open Quick Assist, or provide a remote-support code.

Microsoft has warned that threat actors are using this cross-tenant impersonation technique to convince employees to approve interactive remote sessions.

Once remote access is granted, attackers can run commands, install malware, discover Active Directory systems, move laterally, and steal data.

One recent campaign involved a malware family called SynkLoader. Researchers found that the malware was delivered through a Microsoft Teams phishing message posing as IT support.

The victim was persuaded to install a malicious MSI file, reportedly hosted on Microsoft Azure storage. Using a Microsoft-hosted location can make the download appear more trustworthy to employees.

Hackers Impersonate IT Help Desk on Teams

After installation, SynkLoader can operate largely in memory and create persistence through scheduled tasks. Researchers identified a module called PhishLocker that displays a fake Windows lock screen designed to resemble the legitimate Windows login screen.

The malware can show the user’s account name and a familiar Windows background image to make the prompt appear authentic.

When the employee enters their password to unlock the computer, the fake screen captures it in plaintext. The attacker does not need to crack a password hash or bypass the login process. The goal is to capture the password the user types.

According to ScamDrill, a fake lock screen can sometimes be identified by pressing Ctrl+Alt+Delete. A genuine Windows lock screen opens the Windows Security screen, while a regular full-screen application cannot replicate this behavior.

Users can also try Alt+Tab. In the SynkLoader case, the fake lock screen was a borderless full-screen window, meaning the task switcher could still appear over it.

The campaign highlights a growing social-engineering risk in collaboration platforms. Employees are usually trained to distrust suspicious emails. However, they may be less cautious when receiving a live Teams message from someone appearing to be IT support.

Organizations should restrict Teams external access to known and trusted domains instead of allowing all external domains. Microsoft specifically recommends limiting external Teams communication, ensuring users can see external sender indicators, and requiring employees to verify unsolicited support requests through a known internal channel.

The most important employee rule is simple: if IT contacts you unexpectedly through Teams, end the chat and verify the request using a phone number, service portal, or contact method your organization already trusts.

Never install software, share a remote-access code, approve screen control, or type a password into an unexpected lock screen without independently confirming the request.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC



Source link