Security1 distinct publisher2 min readUpdated
Expel's teardown of a loader first compiled around 28 July 2026 puts the whole delivery chain outside email, and says its module hashes change with every infection.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The reusable detection surface here is a sequence of process events, not a file. The MSI pulled from Azure extracts a PowerShell script called cleaner.ps1 plus a ZIP containing a Python framework, precompiled Python libraries, a malicious Python script and several DLLs posing as Microsoft runtimes [5]. Process lineage catches that shape whether or not anyone holds the hashes, which is fortunate, because Expel's own caveat is that the module hashes are unique per infection and therefore of little use to defenders [20]. A published module hash from this family matches the one infection it was taken from and nothing else [4].
The persistence module tells the same story at smaller scale. It writes a randomly named scheduled task that fires at user logon and again daily at 10 a.m. [10]. The name is unmatchable by design. The pair of triggers is not, and a 10 a.m. task created by a Python process is a query somebody can actually write.
The password capture is what makes the rest worth building. PhishLocker paints a fake Windows lock screen to harvest the account password [11], and the TrafficRedirector module stands up a reverse proxy into internal services [12]. Expel's assessment is that the two together let the operator reach corporate environments from the infected device, past IP allow-listing [16]. The lock screen is a full-screen borderless GUI application, so Alt+Tab exposes the real windows behind it [17], and Expel's advice for an unexpected lock screen is Ctrl+Alt+Delete or Alt+Tab [21].
Expel wrote an emulator for the reverse shell module and watched an operator run profiling commands before disconnecting once it became clear the environment was not real [19]. Marcus Hutchins reads the family's interest in sizing Active Directory as a sign it is used in ransomware operations [18]; the System Profiler module does collect the Active Directory computer count alongside privilege level, running services and domain details [9]. Which modules land at all is decided after entry, from the environment profile and the operator's targets [6].
Four languages appear across the family, with as many as three inside a single module [7][2]. That is mostly an analyst tax, though it also means detection content written against one interpreter will only ever see part of the same intrusion.
None of the documented delivery stages involve email [3]. It opens in a Teams conversation with somebody claiming to be the target company's own IT help desk [1][2], a tactic Microsoft flagged earlier this year as increasingly common in multi-stage attacks [2], and the installer is served from Azure, which Hutchins notes makes the download look trustworthy [3].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen.
The attacker impersonates the target company's IT help desk, a tactic Microsoft highlighted earlier this year as increasingly common in multi-stage attacks.
Expel security researcher Marcus Hutchins says the attacks direct the victim to install a fake "PowerShell Cleaner" executable (.MSI) hosted in Microsoft Azure, making the download appear trustworthy.
Analysis showed compile dates and file timestamps indicating SynkLoader was first compiled and distributed around July 28, 2026.
The installer extracts a PowerShell script named cleaner.ps1 and a ZIP archive containing the Python framework, a malicious Python script, precompiled Python libraries, and several fake Microsoft runtime DLLs.
Based on the breached environment profile and operational targets, the attackers select which modules to deploy.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed single-vendor teardown, no external corroboration
The technical substance is unusually concrete for a new-family report: a named researcher, compile-date analysis, installer contents, a seven-module inventory obtained from a live C2 via honeypot, an emulator run that captured operator behaviour, and published IoCs with an explicit caveat about their limited value. What holds the score down is that everything derives from one vendor relayed by one outlet, with no second research team, CERT advisory, or platform-vendor confirmation, and no disclosed campaign scale.
Confirmed live campaign, undisclosed scale
There is real-world activity rather than a lab finding - an operator was observed working interactively against Expel's decoy, and artefacts date to late July 2026 - but the reporting gives no victim count, no affected sectors or regions, no number of observed intrusions, and no ransomware deployment. Adoption is therefore confirmed as non-zero and recent but cannot be sized.
Mechanics well-supported, impact framing runs ahead
The capability descriptions match the evidence closely, and the outlet even undercuts its own alarm by noting Alt+Tab defeats the fake lock screen and that the published hashes are of little use. The overstatement is modest and sits in the framing: 'previously unknown family' and a probable ransomware role are asserted from one vendor's dataset with no victim scale, no attribution, and no ransomware deployment observed, while the email-bypass angle is a derived reading of the described chain rather than a measured detection-failure result.
Vendor research with visible commercial surround
The findings originate with Expel, a commercial security provider whose honeypot-and-emulator narrative doubles as a demonstration of its detection and response capability, and the article closes with a promotion for a third-party 'Blue Report 2026' simulation study. That does not impeach the technical detail, but the disclosure of limited IoC value and a trivial lock-screen defeat cuts against pure marketing incentive, so the reading is moderate rather than high.
Technically credible, structurally single-sourced
Confidence is limited by cluster shape rather than by weak reporting: one publisher, one vendor, one campaign snapshot, and the highest-stakes elements - scale, attribution, and ransomware intent - are unverified. The mechanics-level claims are internally consistent, method-anchored, and candid about their own limits, which supports a mid-range reading rather than a low one.
product
Microsoft never announced a China exit. Five years of filings did it instead1 distinct publisher
leadership
Microsoft puts AI agents in Entra, which makes agent sprawl an identity team problem1 distinct publisher
product
Agent-to-agent email is already here. The disclosure rule is not.1 distinct publisher
invest
Nvidia and Microsoft bet nuclear's bottleneck is paperwork, not capital1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 21, 2026