Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

New SynkLoader malware pushed in Microsoft Teams phishing campaign

0
High
Published: 08/21/2026 (08/21/2026, 18:01:30 UTC)
Source: Bleeping Computer

Description

SynkLoader is a newly identified malware family distributed via Microsoft Teams phishing campaigns that impersonate IT help desks to steal Windows credentials using a fake lock screen. It uses a multi-language modular architecture combining Python, PowerShell, C#, and C++ to perform system profiling, persistence, credential theft, traffic redirection, and remote control. The malware's PhishLocker module displays a convincing fake Windows lock screen to capture user passwords, enabling attackers to bypass network restrictions and potentially conduct ransomware operations. The malware is delivered as a fake 'PowerShell Cleaner' MSI installer hosted on Microsoft Azure, making it appear trustworthy. Indicators of compromise are unique per infection, complicating detection. Users are advised to verify IT requests independently and use Ctrl+Alt+Delete or Alt+Tab to detect fake lock screens.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/21/2026, 18:07:24 UTC

Technical Analysis

SynkLoader is a previously unknown malware family distributed through Microsoft Teams phishing campaigns that impersonate corporate IT help desks. The attack delivers a fake 'PowerShell Cleaner' MSI installer hosted on Microsoft Azure. The malware extracts a PowerShell script and a ZIP archive containing Python frameworks, malicious scripts, and fake DLLs. SynkLoader's modular design includes components for system profiling, persistence via scheduled tasks, credential theft through a fake Windows lock screen (PhishLocker), traffic redirection via a reverse proxy, remote PowerShell command execution, and desktop streaming with remote control. The PhishLocker module attempts to capture Windows account passwords by displaying a full-screen borderless GUI mimicking the lock screen, which can be exposed by Alt+Tab. The malware focuses on Active Directory environment profiling, suggesting use in ransomware operations. Unique module hashes per infection limit signature-based detection. Best practices include independent verification of IT requests and using Ctrl+Alt+Delete or Alt+Tab to detect fake lock screens.

Potential Impact

Successful compromise allows attackers to steal Windows account credentials, enabling them to bypass IP allow-list restrictions and gain persistent access to corporate environments. The malware's modules enable extensive reconnaissance, persistence, credential theft, network traffic redirection, and remote control of infected systems. This facilitates hands-on-keyboard attacks and potentially supports ransomware operations. The fake lock screen can deceive users into disclosing passwords, increasing the risk of credential theft and lateral movement within networks.

Defensive Guidance

No official patch or vendor advisory is available for SynkLoader malware. Mitigation focuses on user awareness and operational security: independently verify all IT help desk requests, especially those delivered via Microsoft Teams or unsolicited MSI installers. Avoid installing unrequested software. When encountering unexpected lock screens, use Ctrl+Alt+Delete or Alt+Tab to verify authenticity, as the fake lock screen is a full-screen application that can be exposed by these key combinations. Employ endpoint detection and response solutions capable of detecting suspicious scheduled tasks and unusual network proxies. Monitor for unusual PowerShell activity and network traffic redirection. Since module hashes vary per infection, rely on behavioral detection rather than signature-based methods.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.69,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.bleepingcomputer.com/news/security/new-synkloader-malware-pushed-in-microsoft-teams-phishing-campaign/","fetched":true,"fetchedAt":"2026-08-21T18:07:11.321Z","wordCount":877}

Threat ID: 6a8893cfacd9273b4983f8e2

Added to database: 08/21/2026, 18:07:11 UTC

Last enriched: 08/21/2026, 18:07:24 UTC

Last updated: 08/21/2026, 20:17:31 UTC

Views: 19

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses