Skip to content

A New Attack Is Targeting Microsoft Teams

OPERATION SAFE DRIVER WEEK (11)

By: Lamar Garrett | Redbird Security

Attackers are finding ways to exploit gaps, and they have moved from email to Microsoft Teams.

A new attack, identified just last week, called SynkLoader, is distributed through Teams. It starts with a message from what looks like IT, asking you to install a routine cleanup tool.

Once installed, it profiles your network, checking how many other computers are connected. This behavior is more typical of a ransomware operation than one focused purely on theft.

Next it throws up a screen that looks exactly like your normal Windows sign-in. It isn’t real, and it never actually checks the password against anything, so whatever gets typed is sent straight to the attacker. That matters more than it sounds like it should, since most agencies use a single sign-on, meaning the password that unlocks a laptop is often the same one used across email, the AMS, and other systems. From there, attackers gain hands-on control of the machine and a tunnel into the systems that were never supposed to be reachable from outside the building.

How To Stay Safe

One way to catch the fake screen before typing anything into it is to hit Ctrl+Alt+Delete. The real Windows menu will appear underneath, because it’s just an application layered over the desktop, a screen attackers cannot fake.

Verify unexpected IT request through a second channel, never by replying to the message itself. Make sure multifactor authentication covers every way into your systems, not just the obvious ones, since a stolen password is far less dangerous if it can’t be reused elsewhere.

Have more than just antivirus running on your devices. Attacks like this are built specifically to slip past traditional antivirus, since it only catches known threats. Endpoint detection and response tools watch for suspicious behavior instead, which is what actually catches something built to evade the basics.

Restrict who can message your team from outside your organization on Teams. And keep security training current enough to include attacks like this one, not just email phishing from a few years ago.

Attackers are constantly evolving how they get in. Staying current on training and having layers built in will protect you and your team from anything that pops up.

 

Archives

Scroll To Top