THE article discusses the detection of a new malware, SynkLoader, identified by Expel security researchers. This malware targets corporate networks using a sophisticated attack chain that employs social engineering via Microsoft Teams. Attackers impersonate IT support to deliver malicious files disguised as maintenance utilities. SynkLoader executes various programming languages to avoid detection, establishes backconnect proxies, and utilizes a fake lock screen to steal credentials.
The malware maintains persistence through scheduled tasks and employs a reverse proxy to tunnel into corporate networks. Recommendations for defense include employee training, blocking unapproved downloads, and implementing multi-factor authentication.