New SynkLoader Malware Uses Fake Windows Lock Screen to Steal Passwords and Pivot Networks
ID: 92a7ba5e-5e2d-5c77-b29e-63e335644753
STIX ID: report--92a7ba5e-5e2d-5c77-b29e-63e335644753
Feed Name: GBHackers
SynkLoader is a newly identified, modular malware framework deployed via Microsoft Teams phishing that uses a fake Windows lock screen to harvest plaintext credentials, in-memory Python/C#/C++/PowerShell components to evade detection, scheduled-task persistence, reverse-proxy tunneling to access internal resources, and remote-interaction tools (VNC, reverse shells). The report provides technical behavior, compilation metadata suggesting late July 2026 activity, C2 domains, and multiple IOCs (MSI URL and SHA256 hashes) for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
