Cybersecurity
SynkLoader spreads in Microsoft Teams phishing campaign
Expel said a new malware family was pushed through Microsoft Teams impersonation messages, using a fake Windows lock screen and other modules to steal credentials and probe infected networks.
- Expel said SynkLoader was distributed through Microsoft Teams phishing campaigns and used a fake lock screen to capture credentials.
- The lure impersonated a target company's IT help desk and pointed victims to a fake "PowerShell Cleaner" MSI hosted in Microsoft Azure.
- Expel said file metadata showed the malware was first compiled and distributed around 28 July 2026, and its honeypot work identified modules for profiling, persistence, tunnelling, remote shell access and VNC control.
- Marcus Hutchins said the focus on Active Directory sizing suggested the malware was being used in ransomware operations.
Expel said attackers used Microsoft Teams messages to pose as a target company's IT help desk. The lure directed victims to install a fake "PowerShell Cleaner" MSI file hosted in Microsoft Azure, and the installer unpacked PowerShell and Python components.
The firm said file timestamps showed the malware was first compiled and distributed around 28 July 2026. After setting up a honeypot against attacker command-and-control traffic, Expel identified modules for system profiling, scheduled-task persistence, traffic redirection, remote PowerShell access, VNC control and status reporting.
The PhishLocker module displayed a fake Windows lock screen to collect the user's password. Expel said the screen was only a borderless full-screen application, and Alt+Tab could reveal the windows beneath it.
Hutchins said the focus on Active Directory size suggested the malware was being used in ransomware operations. Expel also said it had published indicators of compromise, while noting that the module hashes were unique to each infection.
Expel advised staff to verify IT requests independently and to avoid unsolicited MSI files. It also suggested Ctrl+Alt+Delete or Alt+Tab when confronted with an unexpected lock screen.
Named in this story
People
- Marcus Hutchins
- Expel security researcher who explained the attacks
Companies
- Microsoft
- highlighted the help-desk impersonation tactic earlier in the year
- Expel
- analysed the malware and published the findings
Products and systems
- SynkLoader
- the malware family distributed in the phishing campaign
- Microsoft Teams
- the messaging platform used for the phishing approach
- Microsoft Azure
- hosted the fake MSI download
- PowerShell Cleaner
- the fake MSI name used as the lure
- System Profiler
- module that collected host and domain details
- Persistence Module
- module that created a scheduled task for logon and daily execution
- PhishLocker
- module that showed a fake lock screen to steal a password
- TrafficRedirector
- module that created a reverse proxy through the infected computer
- Interactive Shell (RAT)
- module that ran remote PowerShell commands
- StreamMaster (VNC)
- module that streamed the desktop and allowed remote control
- Module Status Script
- module that reported which components were running
- Active Directory
- the environment whose size the malware profiled
How the source tells it
Mostly a technical report, with mild novelty framing, a speculative ransomware inference, and a brief promotional close.
- novelty the malware was introduced as previously unknown and given a coined name
- speculation a ransomware link was inferred from one profiling behaviour
- reassurance the ending gave defensive checks and verification steps
- vendor boosterism the close shifted into a report promotion built on large simulation totals