ARTIFICE DAILY AI + CYBER SECURITY BRIEFING

Cybersecurity

SynkLoader spreads in Microsoft Teams phishing campaign

Expel said a new malware family was pushed through Microsoft Teams impersonation messages, using a fake Windows lock screen and other modules to steal credentials and probe infected networks.

BleepingComputer

Expel said attackers used Microsoft Teams messages to pose as a target company's IT help desk. The lure directed victims to install a fake "PowerShell Cleaner" MSI file hosted in Microsoft Azure, and the installer unpacked PowerShell and Python components.

The firm said file timestamps showed the malware was first compiled and distributed around 28 July 2026. After setting up a honeypot against attacker command-and-control traffic, Expel identified modules for system profiling, scheduled-task persistence, traffic redirection, remote PowerShell access, VNC control and status reporting.

The PhishLocker module displayed a fake Windows lock screen to collect the user's password. Expel said the screen was only a borderless full-screen application, and Alt+Tab could reveal the windows beneath it.

Hutchins said the focus on Active Directory size suggested the malware was being used in ransomware operations. Expel also said it had published indicators of compromise, while noting that the module hashes were unique to each infection.

Expel advised staff to verify IT requests independently and to avoid unsolicited MSI files. It also suggested Ctrl+Alt+Delete or Alt+Tab when confronted with an unexpected lock screen.

Named in this story

People

Marcus Hutchins
Expel security researcher who explained the attacks

Companies

Microsoft
highlighted the help-desk impersonation tactic earlier in the year
Expel
analysed the malware and published the findings

Products and systems

SynkLoader
the malware family distributed in the phishing campaign
Microsoft Teams
the messaging platform used for the phishing approach
Microsoft Azure
hosted the fake MSI download
PowerShell Cleaner
the fake MSI name used as the lure
System Profiler
module that collected host and domain details
Persistence Module
module that created a scheduled task for logon and daily execution
PhishLocker
module that showed a fake lock screen to steal a password
TrafficRedirector
module that created a reverse proxy through the infected computer
Interactive Shell (RAT)
module that ran remote PowerShell commands
StreamMaster (VNC)
module that streamed the desktop and allowed remote control
Module Status Script
module that reported which components were running
Active Directory
the environment whose size the malware profiled

How the source tells it

Mostly a technical report, with mild novelty framing, a speculative ransomware inference, and a brief promotional close.

  • novelty the malware was introduced as previously unknown and given a coined name
  • speculation a ransomware link was inferred from one profiling behaviour
  • reassurance the ending gave defensive checks and verification steps
  • vendor boosterism the close shifted into a report promotion built on large simulation totals