SynkLoader is a modular Windows loader and post-compromise toolkit distributed through targeted Microsoft Teams spear-phishing and voice-phishing campaigns that impersonate corporate IT or helpdesk personnel. Victims are persuaded to install a fraudulent update-themed MSI package, which launches obfuscated PowerShell, deploys a bundled Python environment, and executes encrypted or memory-resident components. SynkLoader uses multiple languages, including PowerShell, Python, C#, and native code, and uses encrypted command-and-control communications to retrieve and execute operator-supplied tasks.
The malware profiles compromised hosts and Active Directory environments, collecting system, account, privilege, process, service, and domain information. It establishes user-level persistence through COM-created scheduled tasks, and its modules can execute PowerShell commands, capture credentials through a fake Windows lock-screen interface, create reverse-proxy tunnels into internal services, and provide interactive shell and VNC-like desktop-control capabilities. SynkLoader has been associated with hands-on-keyboard intrusions against corporate Windows environments. Its reconnaissance of Active Directory scale, credential collection, tunneling, and remote-control functions are consistent with activity that can enable enterprise access, lateral movement, and follow-on ransomware or extortion operations, although no named threat actor attribution is established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
“To maintain system access, the loader establishes a scheduled task... The task runs whenever a user logs in and repeats daily at 10 AM.”
By using legitimate Azure Blob Storage for delivery and keeping key activity in memory, it can make a harmful download look less suspicious while reducing the traces left for defenders.
“The installer executes the script immediately... The initial PowerShell script decodes an encrypted block directly into system memory,” and a C# module “executes arbitrary PowerShell commands in memory.”
“Next, it extracts a standalone Python runtime environment and the primary loader script named ss.py. The main Python loader initiates system profiling.”
The bootstrap obtains a portable Node.js runtime and uses it to decrypt and execute the JavaScript implant from a user-writable directory.
The MSI installs a script-based loader and a separate encrypted implant file; at runtime, the loader decrypts the JavaScript implant either in memory or into a temporary JavaScript file.
“The sender uses a standard Microsoft 365 default tenant domain to appear credible,” and the downloaded MSI is titled “PowershellCleaner.”
The opening move is simple: a message or call that appears to come from an internal IT worker.
“The initial PowerShell script decodes an encrypted block directly into system memory.”
The DLL is simply an elaborate graphical user interface (GUI), designed to mimic a Windows lock screen... the "PhishLocker" DLL prevents victims from exiting out of the screen until they provide their Windows account password.
another that streams the victim's desktop and enables mouse and keyboard takeover
the local user's privileges, their Active Directory (AD) domain name, and how many other computers belong to their AD network
The DLL is simply an elaborate graphical user interface (GUI), designed to mimic a Windows lock screen... the "PhishLocker" DLL prevents victims from exiting out of the screen until they provide their Windows account password.
another that streams the victim's desktop and enables mouse and keyboard takeover
a malicious Python script that beacons back to the attacker's command-and-control (C2) domains
The recovered implant communicates through randomized HTTPS long-polling requests.
A TrafficRedirector module extends that risk by acting as a reverse proxy through the infected device.
Yet another creates a reverse proxy, enabling them to leverage the victim computer's IP address to route Internet traffic and reach internal services otherwise only accessible via the victim organization's local area network (LAN).
“TrafficRedirector... establishes an outbound connection to an external relay server. It routes traffic back into the local corporate network.”
“The operator hosts this file on a Microsoft Azure Blob storage URL... The downloaded file arrives as an MSI package titled PowershellCleaner.”
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A script-based loader/backdoor delivered in a malicious MSI. It stages a portable Node.js runtime, decrypts and executes an obfuscated JavaScript implant, establishes randomized HTTPS C2 polling, executes operator-supplied JavaScript, performs reconnaissance and screen capture, and supports WinRM lateral movement.
A loader detection associated in this reference with the malicious MSI-based staging chain, which deploys a portable Node.js runtime and executes an encrypted JavaScript implant.
A modular, largely memory-resident loader delivered as a fraudulent MSI package. It profiles enterprise hosts and Active Directory environments, executes PowerShell in memory, establishes COM-based scheduled-task persistence, uses a modified ChaCha20-based C2 protocol, steals plaintext credentials through a fake Windows lock screen, and supports reverse-proxy tunneling plus interactive remote access.
A hash-gated PowerShell loader delivered via fraudulent MSI installers in Microsoft Teams and vishing-based IT support impersonation attacks. It decrypts payloads in memory, verifies a cryptographic hash before execution, and is designed to hinder sandboxing and static analysis.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.