Follow the latest coverage, related explainers and connected technology stories.
Microsoft Threat Intelligence observed a human-operated intrusion campaign in which attackers impersonate support employees through Microsoft Teams, then abuse remote-control sessions to install Node.js-based malware and move within an Active Directory environment. The attack relies on legitimate tools, making it difficult to distinguish from routine support operations and potentially paving the way for data theft or ransomware deployment.
Expel identified new malware named SynkLoader distributed by impersonating Microsoft Teams IT support employees and using a fake lock screen to steal Windows passwords. The malware combines tools for reconnaissance, persistence, and remote control, and may be used as a precursor to ransomware attacks.