Skip to content

Security2 publishersReports disagree2 min readPublished Updated

SynkLoader arrives by Teams help-desk chat and an Azure MSI, so the mail gateway sees nothing

Expel's teardown of a loader first compiled around 28 July 2026 puts the whole delivery chain outside email, and says its module hashes change with every infection.

The Watch · Security desk

How we use AISend a correction

What happened

  • Expel documented a previously unknown loader, SynkLoader, pushed through Microsoft Teams phishing that harvests credentials with a fake lock screen.
  • The lure is a fake "PowerShell Cleaner" MSI hosted in Microsoft Azure, which the researcher says makes the download look trustworthy.
  • Compile dates and file timestamps put the first build and distribution at around 28 July 2026.
  • A honeypot posing as a victim and pinging the attacker's C2 drew down seven separate modules, from system profiling to VNC-style desktop control.
  • Expel published indicators of compromise while warning that the per-infection module hashes among them are not much use.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint Hash-based blocking has nothing durable to match, which pushes the burden onto MSI and PowerShell execution paths and scheduled-task creation that most shops log but few alert on.
  • exposure A stolen Windows password used through the loader's own proxy turns an allow-listed corporate endpoint into the attacker's access point, so network location stops carrying trust.
  • decision Teams collaboration telemetry stops being optional for anyone whose phishing programme is funded and staffed around mail flow.
  • precedent If the ransomware read is right, help-desk impersonation plus cloud-hosted installers becomes a delivery pattern to expect from crews with money, not a one-off.

The reusable detection surface here is a sequence of process events, not a file. The MSI pulled from Azure extracts a PowerShell script called cleaner.ps1 plus a ZIP containing a Python framework, precompiled Python libraries, a malicious Python script and several DLLs posing as Microsoft runtimes [7]. Process lineage catches that shape whether or not anyone holds the hashes, which is fortunate, because Expel's own caveat is that the module hashes are unique per infection and therefore of little use to defenders [19]. A published module hash from this family matches the one infection it was taken from and nothing else [24].

The persistence module tells the same story at smaller scale. It writes a randomly named scheduled task that fires at user logon and again daily at 10 a.m. [12]. The name is unmatchable by design. The pair of triggers is not, and a 10 a.m. task created by a Python process is a query somebody can actually write.

The password capture is what makes the rest worth building. PhishLocker paints a fake Windows lock screen to harvest the account password [4], and the TrafficRedirector module stands up a reverse proxy into internal services [13]. Expel's assessment is that the two together let the operator reach corporate environments from the infected device, past IP allow-listing [17]. The lock screen is a full-screen borderless GUI application, so Alt+Tab exposes the real windows behind it [5], and Expel's advice for an unexpected lock screen is Ctrl+Alt+Delete or Alt+Tab [20].

Expel wrote an emulator for the reverse shell module and watched an operator run profiling commands before disconnecting once it became clear the environment was not real [18]. Marcus Hutchins reads the family's interest in sizing Active Directory as a sign it is used in ransomware operations [6]; the System Profiler module does collect the Active Directory computer count alongside privilege level, running services and domain details [11]. Which modules land at all is decided after entry, from the environment profile and the operator's targets [8].

Four languages appear across the family, with as many as three inside a single module [9][23]. That is mostly an analyst tax, though it also means detection content written against one interpreter will only ever see part of the same intrusion.

None of the documented delivery stages involve email [21]. It opens in a Teams conversation with somebody claiming to be the target company's own IT help desk [1][2], a tactic Microsoft flagged earlier this year as increasingly common in multi-stage attacks [2], and the installer is served from Azure, which Hutchins notes makes the download look trustworthy [3].

What to watch

  • Whether the Azure hosting used for the MSI is attributed to a specific tenant or storage account, and whether Microsoft reports takedowns.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence62
Adoption
Insufficient
Hype gap+5
Incentives
Insufficient
Confidence60
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen.

  2. [2]

    The attacker impersonates the target company's IT help desk, a tactic Microsoft highlighted earlier this year as increasingly common in multi-stage attacks.

  3. [3]

    Expel security researcher Marcus Hutchins says the attacks direct the victim to install a fake "PowerShell Cleaner" executable (.MSI) hosted in Microsoft Azure, making the download appear trustworthy.

Sources

2 independent publishers whose own reporting we read for this story.

  1. bleepingcomputer.com

    1 article · August 21, 2026

    New SynkLoader malware pushed in Microsoft Teams phishing campaign
  2. thehackernews.com

    1 article · August 24, 2026

    WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories