New SynkLoader malware pushed in Microsoft Teams phishing campaign

A New Malware Family Emerges in Microsoft Teams Phishing Campaigns, Threatens Corporate Credentials and Data

In a disturbing trend, cybercriminals have started using a previously unknown malware family called SynkLoader to steal sensitive information from unsuspecting victims through fake Microsoft Teams phishing campaigns. This malicious software, dubbed “SynkLoader,” is designed to extract credentials, profile systems, and even gain remote control over compromised devices.

The attackers pretend to be the target company’s IT help desk, a tactic that has become increasingly common in multi-stage attacks, as highlighted by Microsoft earlier this year. Victims are directed to download a fake “PowerShell Cleaner” executable (.MSI) hosted on Microsoft Azure, which appears trustworthy but actually installs SynkLoader malware.

Analysis of the malware revealed that it was first compiled and distributed around July 28, 2026. The installer extracts various malicious components, including a PowerShell script named cleaner.ps1, a ZIP archive containing the Python framework, precompiled Python libraries, and several fake Microsoft runtime DLLs. Based on the breached environment profile and operational targets, the attackers select which modules to deploy.

SynkLoader’s unique feature is its combination of multiple programming languages – Python, PowerShell, C#, and C++ – sometimes blending up to three in a single module. Expel’s security researcher Marcus Hutchins identified several SynkLoader modules after setting up a honeypot that pings the attacker’s command-and-control (C2) server, posing as a legitimate victim.

The most disturbing aspect of SynkLoader is its PhishLocker module, which attempts to obtain the victim’s Windows account password via a fake lock screen. By obtaining this sensitive information, attackers can use it alongside the tunneling module to access corporate environments from the infected device, bypassing IP allow-list restrictions. Although the fake lock screen appears convincing, simply using Alt+Tab exposes the active windows on top of the lock screen.

Hutchins believes that SynkLoader is likely used in ransomware operations due to its focus on measuring Active Directory environment size. The researcher also notes that once attackers have valid credentials, only 37% of their actions are blocked, highlighting the need for robust prevention measures.

To protect against these types of attacks, users should verify IT requests independently and avoid installing unsolicited MSI files. When met with an unexpected lock screen, try Ctrl+Alt+Delete or Alt+Tab to determine its authenticity. By being vigilant and taking proactive steps, individuals can reduce their risk of falling victim to SynkLoader malware.

In today’s increasingly complex threat landscape, it is essential for organizations and individuals to stay informed about emerging threats like SynkLoader. By understanding the tactics and techniques used by cybercriminals, we can better prepare ourselves against these types of attacks and protect our sensitive information.


Source: Bleeping Computer — 2026-08-21