Security2 publishersReports disagree2 min readPublished Updated
SynkLoader arrives by Teams help-desk chat and an Azure MSI, so the mail gateway sees nothing
Expel's teardown of a loader first compiled around 28 July 2026 puts the whole delivery chain outside email, and says its module hashes change with every infection.
The Watch · Security desk
What happened
- Expel documented a previously unknown loader, SynkLoader, pushed through Microsoft Teams phishing that harvests credentials with a fake lock screen.
- The lure is a fake "PowerShell Cleaner" MSI hosted in Microsoft Azure, which the researcher says makes the download look trustworthy.
- Compile dates and file timestamps put the first build and distribution at around 28 July 2026.
- A honeypot posing as a victim and pinging the attacker's C2 drew down seven separate modules, from system profiling to VNC-style desktop control.
- Expel published indicators of compromise while warning that the per-infection module hashes among them are not much use.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint Hash-based blocking has nothing durable to match, which pushes the burden onto MSI and PowerShell execution paths and scheduled-task creation that most shops log but few alert on.
- exposure A stolen Windows password used through the loader's own proxy turns an allow-listed corporate endpoint into the attacker's access point, so network location stops carrying trust.
- decision Teams collaboration telemetry stops being optional for anyone whose phishing programme is funded and staffed around mail flow.
- precedent If the ransomware read is right, help-desk impersonation plus cloud-hosted installers becomes a delivery pattern to expect from crews with money, not a one-off.
The reusable detection surface here is a sequence of process events, not a file. The MSI pulled from Azure extracts a PowerShell script called cleaner.ps1 plus a ZIP containing a Python framework, precompiled Python libraries, a malicious Python script and several DLLs posing as Microsoft runtimes [7]. Process lineage catches that shape whether or not anyone holds the hashes, which is fortunate, because Expel's own caveat is that the module hashes are unique per infection and therefore of little use to defenders [19]. A published module hash from this family matches the one infection it was taken from and nothing else [24].
The persistence module tells the same story at smaller scale. It writes a randomly named scheduled task that fires at user logon and again daily at 10 a.m. [12]. The name is unmatchable by design. The pair of triggers is not, and a 10 a.m. task created by a Python process is a query somebody can actually write.
The password capture is what makes the rest worth building. PhishLocker paints a fake Windows lock screen to harvest the account password [4], and the TrafficRedirector module stands up a reverse proxy into internal services [13]. Expel's assessment is that the two together let the operator reach corporate environments from the infected device, past IP allow-listing [17]. The lock screen is a full-screen borderless GUI application, so Alt+Tab exposes the real windows behind it [5], and Expel's advice for an unexpected lock screen is Ctrl+Alt+Delete or Alt+Tab [20].
Expel wrote an emulator for the reverse shell module and watched an operator run profiling commands before disconnecting once it became clear the environment was not real [18]. Marcus Hutchins reads the family's interest in sizing Active Directory as a sign it is used in ransomware operations [6]; the System Profiler module does collect the Active Directory computer count alongside privilege level, running services and domain details [11]. Which modules land at all is decided after entry, from the environment profile and the operator's targets [8].
Four languages appear across the family, with as many as three inside a single module [9][23]. That is mostly an analyst tax, though it also means detection content written against one interpreter will only ever see part of the same intrusion.
None of the documented delivery stages involve email [21]. It opens in a Teams conversation with somebody claiming to be the target company's own IT help desk [1][2], a tactic Microsoft flagged earlier this year as increasingly common in multi-stage attacks [2], and the installer is served from Azure, which Hutchins notes makes the download look trustworthy [3].
What to watch
- Whether the Azure hosting used for the MSI is attributed to a specific tenant or storage account, and whether Microsoft reports takedowns.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence60
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen.
- [2]
The attacker impersonates the target company's IT help desk, a tactic Microsoft highlighted earlier this year as increasingly common in multi-stage attacks.
- [3]
Expel security researcher Marcus Hutchins says the attacks direct the victim to install a fake "PowerShell Cleaner" executable (.MSI) hosted in Microsoft Azure, making the download appear trustworthy.
- [4]
The PhishLocker module displays a convincing fake Windows lock screen to capture the user's login password.
- [5]
Expel notes that using Alt+Tab exposes the active windows on top of the fake lock screen, which is just a full-screen borderless GUI application.
- [6]
Hutchins says that based on SynkLoader's focus on measuring Active Directory environment size, it is likely used in ransomware operations.
- [7]
The installer extracts a PowerShell script named cleaner.ps1 and a ZIP archive containing the Python framework, a malicious Python script, precompiled Python libraries, and several fake Microsoft runtime DLLs.
- [8]
Based on the breached environment profile and operational targets, the attackers select which modules to deploy.
- [9]
SynkLoader was named for its unusual combination of Python, PowerShell, C# and C++, sometimes blending up to three programming languages in a single module.
- [10]
Expel identified the SynkLoader modules after setting up a honeypot pinging the attacker's C2, posing as a legitimate victim.
- [11]
The System Profiler module collects the hostname, username, privilege level, running processes, services, domain details, and number of computers in Active Directory.
- [12]
The Persistence module creates a randomly named scheduled task that launches SynkLoader at user logon and daily at 10 a.m.
- [13]
The TrafficRedirector module creates a reverse proxy that lets attackers reach internal network services or route internet traffic through the infected computer.
- [14]
The Interactive Shell (RAT) module allows attackers to remotely execute PowerShell commands and receive their output.
- [15]
The StreamMaster (VNC) module streams the victim's desktop and enables remote mouse and keyboard control of the active session.
- [16]
A Module Status Script reports which malware modules and associated threads are currently running.
- [17]
By obtaining the password, the attackers could use it alongside the tunneling module to access corporate environments from the infected device, bypassing IP allow-list restrictions.
- [18]
Expel wrote an emulator for the reverse shell module to confirm a hands-on-keyboard attack; the threat actor ran several profiling commands before realising they were not in a real environment and disconnecting.
- [19]
Expel provided indicators of compromise for the observed attack but noted the SynkLoader module hashes are unique for each infection and therefore not very useful for defenders.
- [20]
Recommended practice is to verify IT requests independently, avoid installing unsolicited MSI files, and try Ctrl+Alt+Delete or Alt+Tab when met with an unexpected lock screen.
- [21]
The documented delivery chain contains no email stage: it runs from a Teams message to an Azure-hosted MSI download to local execution of cleaner.ps1.
- [22]
Expel's honeypot work documented seven distinct SynkLoader modules.
- [23]
Four programming languages are named across the family, with up to three of them inside one module.
- [24]
Because module hashes are unique per infection, any published module hash matches only the single infection it was collected from, giving zero reuse across victims.
- [25]
Analysis showed compile dates and file timestamps indicating SynkLoader was first compiled and distributed around July 28, 2026.
Sources
2 independent publishers whose own reporting we read for this story.
- bleepingcomputer.comNew SynkLoader malware pushed in Microsoft Teams phishing campaign
1 article · August 21, 2026
- thehackernews.comWordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
1 article · August 24, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Help desk impersonationFollow
- Phishing over collaboration appsFollow
- Malware loaders and delivery chainsFollow
- Credential Theft and Stealer LogsFollow
Entities
- MicrosoftFollow
- Marcus HutchinsFollow
- ExpelFollow
- BleepingComputerFollow
- The Hacker NewsFollow
- SynkLoaderFollow
- Microsoft TeamsFollow
- Microsoft AzureFollow