logo

New SynkLoader Malware Uses Fake Windows Lock Screen to Steal Passwords and Pivot Networks

ID: 92a7ba5e-5e2d-5c77-b29e-63e335644753

STIX ID: report--92a7ba5e-5e2d-5c77-b29e-63e335644753

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-08-24

Date Updated: 2026-08-24

Author: Mayura Kathir

...
...

SynkLoader is a newly identified, modular malware framework deployed via Microsoft Teams phishing that uses a fake Windows lock screen to harvest plaintext credentials, in-memory Python/C#/C++/PowerShell components to evade detection, scheduled-task persistence, reverse-proxy tunneling to access internal resources, and remote-interaction tools (VNC, reverse shells). The report provides technical behavior, compilation metadata suggesting late July 2026 activity, C2 domains, and multiple IOCs (MSI URL and SHA256 hashes) for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.