Many people are used to getting messages from their company's IT department when something goes wrong with their computer. Perhaps there's a security update to install, a problem with the account, or some software that needs fixing.
Unfortunately, criminals know this — and they're now using that trust to trick people.
Security researchers have warned about a new scam involving Microsoft Teams in which criminals pretend to be members of a company's IT helpdesk. Their aim is to persuade employees to install malicious software that can give attackers access to their computer and potentially their passwords.
The malware involved has been identified as SynkLoader, a type of malicious software that can allow criminals to control an infected computer and steal information.
How does the scam work?
The attack is surprisingly simple because it relies less on complicated technology and more on trust.
An employee receives a message through Microsoft Teams from someone claiming to work in the company's IT department.
The supposed IT worker tells them that there is a problem with their computer and says they need to install a program called "PowerShell Cleaner" to fix it.
It sounds reasonable. After all, if someone from IT tells you there's a problem, why wouldn't you follow their instructions?
That's exactly what the criminals are counting on.
The "cleaner" isn't really a helpful computer maintenance program. It's malicious software designed to give the attacker access to the computer. Researchers at cybersecurity company Expel found that the malicious software was even hosted using Microsoft's Azure cloud service, which could make it appear more trustworthy to someone who isn't expecting a scam.
What happens if you install it?
The consequences can be serious.
SynkLoader contains different components that can perform different jobs. One particularly worrying component can display a fake Windows login screen.
It looks as though Windows is asking you to enter your password. But instead of logging you into your computer, the fake screen can capture the password and send it to the criminal.
Another component can give the attacker a way to remotely control the infected computer and run commands on it. In simple terms, the criminal may be able to operate your computer from a distance.
That could potentially give them access to files, company systems and other information available from the compromised computer.
Why is this scam so convincing?
The clever part isn't necessarily the malware. It's the story surrounding it.
Imagine receiving this Teams message:
"Hi, I'm from IT. We've noticed a problem with your computer. Please install this cleaner and I'll help you fix it."
Many people would naturally assume that the person is genuine.
This is known as social engineering. Rather than breaking through a computer's security by force, criminals manipulate people into doing something that helps them.
It's the same basic trick behind many email scams — except this time, the message arrives through a tool you use every day for work.
And because Microsoft Teams is normally associated with colleagues and business communications, an unexpected message can feel more trustworthy than a suspicious email.
What should you do if you receive a message like this?
The most important rule is simple:
Don't install software just because someone tells you to in a Teams message.
If someone claiming to be IT contacts you unexpectedly, stop and check.
1. Contact your companies IT department separately
Don't use the contact details provided by the person who messaged you.
Instead, use a phone number, email address or support system that you already know belongs to your company's IT department.
Ask something like:
"Did you just contact me about installing software on my computer?"
If the answer is no, you've probably avoided a scam.
2. Be suspicious of unexpected software requests
Your IT department may genuinely need you to install software from time to time. That's normal.
But an unexpected request to download a program should always be verified first — particularly if you're being told to install something urgently.
3. Don't be embarrassed about checking
Scammers often try to create a sense of urgency.
They might say your computer is infected, your account is about to be disabled, or there's a serious problem that needs fixing immediately.
Don't let that pressure you into making a quick decision.
A genuine IT department should understand if you want to verify someone's identity before installing software.
4. Never give away your password
Be especially careful if you're asked to enter your Windows or company password into an unfamiliar window.
If something looks unusual, stop and contact IT.
What if you've already installed something?
Don't panic — but don't ignore it either.
Stop communicating with the person who contacted you and contact your company's IT or security team immediately.
Tell them exactly what happened, including what software you were asked to install and roughly when you installed it.
If you've entered a password into a suspicious screen, tell IT that too. They may need to secure your account and check whether anything else has been accessed.
The bigger lesson
This latest attack is a reminder that cybersecurity isn't only about antivirus software and complicated technical protections.
Sometimes the biggest vulnerability is simply trust.
Criminals know that people are more likely to follow instructions from someone who appears to be a colleague, a manager or a member of IT. Microsoft Teams provides another way for them to exploit that trust.
So the next time an unexpected "IT Support" message appears in Teams, don't automatically assume it's genuine.
Stop. Check who the person really is. Contact your IT department or if your company does not have an IT department, you can always contact ourselves at Direct Computers.
Never install anything until you've confirmed the request.
Taking an extra minute to check could prevent a much bigger problem later.