SynkLoader Malware Spreads Through Microsoft Teams Phishing and Steals Windows Passwords
ID: 9da6db8c-1349-58fe-867b-061cf83f4f5c
STIX ID: report--9da6db8c-1349-58fe-867b-061cf83f4f5c
Feed Name: Cyber Press
SynkLoader is a sophisticated malware loader observed in August 2026 that combines Python, C#, and native C++ to evade detection, deploy an embedded Python runtime, harvest plaintext Windows credentials via a fake Windows 11 lock screen (PhishLocker), and provide a backconnect proxy for lateral movement and access to internal resources; initial delivery used a spoofed Microsoft Teams message and an MSI hosted on Azure Blob Storage, with researchers observing C2 domains, scheduled task persistence, and modules suggesting ties to ransomware or initial-access brokers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
