SynkLoader: when you throw in everything but the kitchen sink
ID: e2746ce3-1bc7-5c60-821a-656b3f98cab0
STIX ID: report--e2746ce3-1bc7-5c60-821a-656b3f98cab0
Feed Name: Expel Blog
This report analyzes a newly observed modular malware family dubbed "SynkLoader" distributed via a Microsoft Teams phishing MSI that deploys an embedded Python runtime and multiple memory-resident modules (PowerShell executor, in-memory DLL loader, scheduled-task persistence, fake Windows lock-screen credential harvester, reverse proxy/tunneling, interactive shell and VNC). The authors reverse-engineered the loader, emulated C2 to capture operator tooling and commands, provide detailed TTPs and IOCs (domains, file hashes, delivery URL), and assess with low–medium confidence the toolkit is likely used to facilitate hands-on-keyboard intrusions and potentially ransomware or initial access resale.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
