Incident
Published 2026-09-02
Verified 2026-09-27

Microsoft Teams: cross-tenant IT helpdesk impersonation → remote session, MSI/Node.js implant; Expel SynkLoader fake lock screen

Microsoft Threat Intelligence (2 September 2026) documents a human-operated campaign abusing Microsoft Teams external collaboration: actors in a separate Microsoft 365 tenant impersonate IT/helpdesk, coax users past external-tenant labels into granting interactive remote access (Teams request-control, Quick Assist, or similar RMM), then use PowerShell to silently install a malicious MSI from cloud storage that stages a portable Node.js runtime and obfuscated JavaScript implant for C2, Active Directory reconnaissance, desktop capture, and WinRM lateral movement toward domain controllers and other high-value hosts. Expel (20 August 2026) independently details a related Teams helpdesk-phishing delivery of SynkLoader (MSI presented as “PowershellCleaner” from an Azure blob endpoint; sender display name IT Service Desk on a *.onmicrosoft.com tenant), including a PhishLocker module that shows a fake Windows lock screen and captures the typed password in plaintext, plus a tunneling module for follow-on access. ScamDrill (17 September 2026) and CyberSecurityNews (22 September) summarize the same pattern for SMB defenders. Not a Teams product CVE — social engineering of legitimate external chat and remote-support features. Distinct from desk card prey-0058-m365-vishing-20260903 (phone vishing + AiTM MFA-registration domains). Australia relevance: M365/Teams tenants with open external access — restrict to trusted domains, verify unsolicited IT chats out-of-band, control Quick Assist/RMM, and hunt MSI→Node.js under LocalAppData plus user-context WinRM.

Product
Microsoft Teams external collaboration / Microsoft 365; Windows hosts (Quick Assist/RMM, MSI, Node.js implant; SynkLoader/PhishLocker variant)
Exploited in Australia?
unknown
Patch to
Restrict Teams external access to trusted domains only; keep external-sender indicators visible; train staff that IT does not cold-open Teams chats — verify via a known internal channel; limit/monitor Quick Assist and other RMM; enable attack-surface reduction rules that block risky script/installer chains; restrict WinRM (TCP 5985) to admin workstations; hunt MSI installs from cloud blobs, Node.js under LocalAppData, and user-context WinRM; rotate credentials if indicators of this campaign are found

Primary: Microsoft Security Blog — Impersonating IT support / Teams remote-session intrusion (2 Sep 2026) · Vendor: Microsoft Learn — Trusted organizations for external meetings and chat · Expel — SynkLoader Teams helpdesk MSI + PhishLocker fake lock screen (20 Aug 2026)

breaches identity cloud