A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen.
The attacker impersonates the target company’s IT help desk, a tactic Microsoft highlighted earlier this year as increasingly common in multi-stage attacks.
Expel’s security researcher Marcus Hutchins explains that the attacks direct the victim to install a fake “PowerShell Cleaner” executable (.MSI) hosted in Microsoft Azure, making the download appear trustworthy.
Analysis of the malware showed “compile dates and file timestamps indicating it was first compiled and distributed around July 28, 2026.”
The installer extracts a PowerShell script named cleaner.ps1 and a ZIP archive containing the Python framework, a malicious Python script, precompiled Python libraries, and several fake Microsoft runtime DLLs.
Based on the breached environment profile and operational targets, the attackers select which modules to deploy.
SynkLoader was named as such because of its unusual combination of Python, PowerShell, C#, and C++, sometimes blending up to three programming languages in a single module.
Expel identified the following SynkLoader modules after setting up a honeypot pinging the attacker’s C2, posing as a legitimate victim:
The most interesting component of SynkLoader is the PhishLocker module, which attempts to obtain the victim’s Windows account password via a fake lock screen.
By obtaining the password, the attackers could use it alongside the tunneling module to access corporate environments from the infected device, bypassing IP allow-list restrictions.
Although the fake lock screen looks particularly convincing, Expel notes that simply using Alt+Tab exposes the active windows on top of the lock screen which is just a “full-screen borderless GUI application.”
Hutchins says that based on SynkLoader’s focus on measuring Active Directory environment size, it’s likely that it’s used in ransomware operations.
“We did end up writing an emulator for the reverse shell module, just to confirm it was actually a hands-on-keyboard attack,” the researcher says.
“The threat actor attempted to run several profiling commands before realizing they were not in a real environment and disconnecting.”
Expel provided indicators of compromise (IoCs) for the observed attack, though it noted that the SynkLoader module hashes are unique for each infection and therefore not very useful for defenders.
The best practice would be to verify IT requests independently and avoid installing unsolicited MSI files.
When met with an unexpected lock screen, try Ctrl+Alt+Delete or Alt+Tab to determine its authenticity.
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Fake IT support calls on Microsoft Teams push EtherRAT malware
ToxicPanda Android malware uses VPN permissions to block Google Play
Hackers infect Android car head units with proxy botnet malware
New Manic Android malware can exfiltrate data through nearby devices
Microsoft blames Windows gaming issues on RGB lighting devices
Hundreds of leaked AWS keys give full control over corporate accounts
Microsoft patches max severity code execution, privilege escalation flaws
Microsoft rolls out Classic Outlook theme for New Outlook users
Protect yourself from data brokers, scammers, and the next data breach with digital identities.
Stay one step ahead of new threats in the new year. Join Huntress for the monthly Tradecraft Tuesday.
Certighost CVE is new. The privilege behind it isn’t. Discover where yours is hiding.
See how AI is reshaping email attacks. Download the 2026 Kaseya Email Security Report.
Signature-based prevention fell to 50%. See what your controls still stop.
Discover how least agency keeps your AI tools capable, controlled, and secure.
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.



