Summary
Expel researchers have identified a new backdoor malware called SynkLoader, which targets Microsoft Teams users through fake IT helpdesk messages. The malware includes modules like PhishLocker for harvesting login credentials and Interactive Shell for remote control, posing a significant threat to corporate environments. Organizations are advised to educate employees on distrusting unsolicited messages and verifying app installations with IT to defend against these social engineering attacks.