A newly identified modular malware family dubbed SynkLoader is being deployed through Microsoft Teams phishing messages that impersonate corporate IT help desks and direct users to install a fake "PowerShell Cleaner" MSI hosted on Azure Blob Storage. Researchers found the infection chain uses in-memory PowerShell execution and a bundled Python runtime to launch a multi-language framework spanning PowerShell, Python, C#, and native C/C++ DLLs, allowing the malware to remain largely memory-resident while profiling infected systems and establishing persistence through a scheduled task created via COM.
SynkLoader supports credential theft and hands-on-keyboard intrusion through several modules, including a fake Windows lock screen component known as PhishLocker that captures user passwords, traffic tunneling through the victim host, interactive PowerShell access, and VNC-style desktop streaming for remote control. By emulating the malware's command-and-control protocol and supplying decoy enterprise telemetry, researchers observed operators deploy additional tooling and conduct Active Directory-focused reconnaissance, leading to a low-to-medium confidence assessment that the activity is tied to a ransomware group or an initial access broker supporting ransomware operations.

Get the infrastructure and lures behind it.
7 events from the most recent confirmed update back to the earliest known activity.
Expel published technical analysis of SynkLoader, including indicators of compromise and defensive guidance. The report documented the malware's modules, phishing delivery method, and techniques such as fake lock-screen credential theft and traffic redirection.
Expel identified the previously unknown SynkLoader malware family on August 18, 2026 while investigating a client incident after an EDR alert flagged a scheduled task. That investigation led researchers to analyze the multi-stage intrusion later documented in Expel's public report.
Analysis cited by Expel indicated the previously unknown SynkLoader malware family was first compiled and distributed around July 28, 2026. Researchers later tied it to Microsoft Teams phishing that impersonated corporate IT help desks.
Based on the operators' focus on Active Directory scale, credential capture, and interactive intrusion behavior, researchers assessed that SynkLoader is likely associated with ransomware activity or an initial access broker serving ransomware actors. The assessment was described with low-to-medium confidence in Expel's reporting.
By emulating the malware's command-and-control protocol and presenting a fake large enterprise Active Directory environment, Expel induced the operators to deploy additional tooling. The response included modules for persistence, credential theft, traffic tunneling, and interactive access, revealing hands-on-keyboard activity.
After analyzing the intrusion, researchers identified a newly discovered modular malware family and named it SynkLoader. They highlighted its unusual multi-language design and memory-resident modules intended to evade detection.
In the observed intrusion, attackers used a Microsoft Teams phishing lure impersonating an IT help desk and convinced a victim to download a fake "PowerShell Cleaner" MSI from Azure Blob Storage. The installer launched a multi-stage malware chain using PowerShell, Python, C#, and native DLL components.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
10 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcemeetcyber.net
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcecyberveille.ch
Open sourcebleepingcomputer.com
Open sourceexpel.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.