logo

New SynkLoader malware pushed in Microsoft Teams phishing campaign

ID: 517c822e-d0c6-5c2f-a6d8-06710f7cde25

STIX ID: report--517c822e-d0c6-5c2f-a6d8-06710f7cde25

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-08-21

Date Updated: 2026-08-21

Author: Bill Toulas

...
...

**Executive summary:** Expel researchers identified SynkLoader, a multi-language malware family distributed through Microsoft Teams phishing that tricks victims into installing a fake "PowerShell Cleaner" MSI hosted in Azure; SynkLoader deploys modules for system profiling, persistence, a PhishLocker fake Windows lock screen to harvest credentials, reverse-proxy tunneling for internal access, an interactive PowerShell shell, and VNC-like desktop streaming, and is likely used to support ransomware operations—defenders should verify IT requests, avoid unsolicited MSIs, and use Ctrl+Alt+Delete or Alt+Tab to detect fake lock screens while leveraging provided IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.