New SynkLoader Malware Spreads Through Microsoft Teams Phishing


microsoft teams malware synkloader
Image credit: Microsoft

SynkLoader malware is being distributed through Microsoft Teams phishing campaigns in which attackers impersonate corporate IT help desks and convince employees to install a malicious MSI package.

The newly identified SynkLoader malware gives attackers several ways to control compromised systems, including credential theft, remote desktop access, reverse proxy capabilities, and an interactive PowerShell shell.

File timestamps examined by researchers suggest the malware was first compiled and distributed around July 28, 2026.

Attackers pose as IT support on Microsoft Teams

The attack begins with threat actors contacting employees through Microsoft Teams while pretending to represent the organization’s IT help desk.

Victims receive instructions to download and install a supposed “PowerShell Cleaner” packaged as an MSI installer. Attackers host the malicious installer on Microsoft Azure, which can make the download appear more legitimate.

Once installed, SynkLoader can deploy different modules depending on the compromised environment and what attackers want to accomplish.

The malware uses an unusual combination of Python, PowerShell, C#, and C++. Some individual modules reportedly use as many as three programming languages.

SynkLoader comes with several attack modules

SynkLoader includes multiple components that attackers can deploy selectively.

  • System Profiler collects the hostname, username, privileges, running processes, services, domain information, and the number of computers in Active Directory.
  • Persistence Module creates a randomly named scheduled task that launches SynkLoader when the user logs in and every day at 10 a.m.
  • PhishLocker displays a fake Windows lock screen designed to steal the user’s password.
  • TrafficRedirector creates a reverse proxy that can provide access to internal services or route traffic through the infected computer.
  • Interactive Shell gives attackers remote PowerShell command execution and returns command output.
  • StreamMaster provides VNC-style remote desktop access, including mouse and keyboard control.
  • Module Status Script reports which SynkLoader components and related threads are currently running.

The modular design allows attackers to adjust the infection based on the value of a compromised system instead of deploying every capability immediately.

Fake Windows 11 lock screen steals passwords

One of SynkLoader’s more unusual components, PhishLocker, creates a convincing imitation of the Windows 11 lock screen.

The malware tries to convince users to enter their Windows account password, giving attackers another way to obtain credentials from the compromised computer.

However, the screen isn’t a real Windows lock screen. It runs as a full-screen borderless application, meaning keyboard shortcuts such as Alt+Tab can reveal other open windows and expose the deception.

Users can also press Ctrl+Alt+Delete if they suspect that an unexpected Windows lock screen isn’t legitimate.

Combined with SynkLoader’s reverse proxy functionality, stolen credentials could give attackers another route into services accessible from the compromised corporate device.

SynkLoader could have a ransomware connection

Researchers also noticed that SynkLoader collects information about the size and structure of Active Directory environments.

Expel researcher Marcus Hutchins believes this focus could indicate that SynkLoader may eventually support ransomware operations, where attackers often need to understand a company’s network before moving laterally and deploying ransomware.

Expel also developed an emulator for SynkLoader’s reverse shell component. Researchers confirmed that attackers conduct hands-on-keyboard activity after compromising systems, rather than relying entirely on automated malware behavior.

How organizations can protect against SynkLoader

Employees should independently verify unexpected requests from anyone claiming to represent internal IT staff, particularly when those requests involve installing software.

Organizations should also discourage users from installing unsolicited MSI packages, even when attackers host those files on legitimate cloud platforms such as Microsoft Azure.

Security teams can look for unusual scheduled tasks, suspicious PowerShell activity, unexpected remote-control behavior, and network tunneling that could indicate SynkLoader activity.

If an unexpected Windows lock screen appears, users can press Ctrl+Alt+Delete or Alt+Tab to determine whether Windows actually locked the device or whether another application is imitating the lock screen.

Microsoft has also recently fixed a major Entra security flaw, while CISA confirmed that a Windows Task Host flaw was abused in ransomware attacks.

Via BleepingComputer

More about the topics: malware, microsoft, Microsoft Teams

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages