logo

SynkLoader Malware Spreads Through Microsoft Teams Phishing and Steals Windows Passwords

ID: 9da6db8c-1349-58fe-867b-061cf83f4f5c

STIX ID: report--9da6db8c-1349-58fe-867b-061cf83f4f5c

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-08-24

Date Updated: 2026-08-24

Author: Tamilselvan

...
...

SynkLoader is a sophisticated malware loader observed in August 2026 that combines Python, C#, and native C++ to evade detection, deploy an embedded Python runtime, harvest plaintext Windows credentials via a fake Windows 11 lock screen (PhishLocker), and provide a backconnect proxy for lateral movement and access to internal resources; initial delivery used a spoofed Microsoft Teams message and an MSI hosted on Azure Blob Storage, with researchers observing C2 domains, scheduled task persistence, and modules suggesting ties to ransomware or initial-access brokers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.