Build1 publisherNot yet confirmed elsewhere3 min readPublished
SynkLoader: the Teams help-desk lure now ships with a reverse proxy attached
Expel's writeup describes a chain with no exploit in it: an external-tenant Teams message, an MSI from Azure Blob, a COM-made scheduled task, a fake lock screen, and a relay into the LAN.
The Engineer · Build desk
What happened
- Expel documented a multi-stage intrusion kit it calls SynkLoader in a report dated 20 August 2026 and rated high severity.
- First contact is a Teams message from an external Microsoft 365 tenant, with the sender posing as the IT service desk.
- The user is talked into running a PowershellCleaner MSI, retrieved as 331.msi from an Azure Blob host and launched through msiexec.
- The installer drops cleaner.ps1 and a zip into LocalAppData, and a COM-created task with a random 12-character name runs ss.py under pythonw.exe.
- Two modules follow: PhishLocker, which harvests the password via a full-screen fake lock screen, and TrafficRedirector, which opens PowerShell shells and VNC over a reverse proxy.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- exposure With the host relaying traffic, the credentials arrive at internal and external services from an employee's own address, so IP allowlists vouch for the intruder instead of stopping it.
- constraint Nothing in the initial approach passes through the mail gateway, so the evidence that matters sits in Teams audit logs, a data set most SOCs neither own nor tune.
- decision Only one of the recommended controls acts before the installer runs, which turns this into a policy argument about external-tenant chat rather than a tooling purchase.
- precedent Because payloads are handed out selectively, an indicator sweep that finds no lock-screen artefacts cannot be reported as a clean host.
Expel lists the preconditions for this chain plainly, and not one of them is a software flaw: the user has to run the MSI, PowerShell and Python and COM task creation have to be unblocked, the user has to type a valid Windows password into the fake lock screen, and C2 delivery has to succeed [12]. There are no CVEs in the writeup and no attributed group [16]. Everything that makes SynkLoader work is a configuration somebody chose, or declined to make.
The traffic side is not quiet if you measure it. A beacon with 90 to 120 second jitter [11] works out to roughly 720 to 960 callbacks per device per day [20]. It survives on destination rather than volume, and one of the three domains Expel names is tripinupdate.net, which is the shape of a string a network reviewer skims past [10].
Module delivery is selective, from multiple C2 servers [9]. Two infected hosts in the same organisation need not be carrying the same payloads, so a sweep for the PhishLocker fake lock screen [6] can come back clean on a machine that is already relaying traffic outward [7]. The stage common to every variant is the cheaper thing to hunt: a randomly named 12-character scheduled task, created through COM, running ss.py under pythonw.exe at logon and again at 10:00 each day [5].
The relay is also why a password reset does not close the ticket. Expel's response sequence puts credential rotation and session revocation alongside cross-checking internal and external authentication from the victim's IP address, investigating the PowerShell and VNC activity that follows the proxy, and hunting for other users contacted by the same external tenant [15]. That last step is the one that decides whether this was one employee or a mailbox-wide sweep of the org.
Of the four mitigations listed, three are blocks applied after the lure lands: MSI execution, Azure Blob downloads and obfuscated PowerShell; COM Task Scheduler creation; C2 and reverse proxy egress [14]. Only restricting external-tenant Teams contact acts before msiexec runs [14], and Expel points the detection work at Teams audit logs rather than email [13], which is a different log source with a different owner in most shops.
Read the confidence ladder in the report before you escalate: it separates an external Teams contact or MSI URL with no execution from confirmed user action, confirmed loader and task creation, and confirmed post-compromise proxy and VNC activity [17]. That distinction is doing real work here, because the first rung will be the most common finding and the cheapest to close. One caveat on sourcing: this account is a dev.to summary crediting Expel as the original [18], with a second writeup listed alongside it on the same campaign [19] rather than an independent confirmation of the artefacts.
What to watch
- Whether Microsoft tightens defaults or adds first-contact friction for chats from unmanaged external tenants, which is the only control that bites before msiexec runs.
- Whether a second responder publishes overlapping C2 or Azure Blob infrastructure, which would separate one crew from a kit in circulation.
- Whether any affected organisation confirms authentication to external SaaS from a victim IP, the allowlist-bypass step that is hardest to see after the fact.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence58
- Adoption20
- Hype gap+14
- Incentives62
- Confidence55
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Expel published a report titled "SynkLoader: when you throw in everything but the kitchen sink" dated 2026-08-20, rated severity high.
- [2]
Attackers contact victims on Microsoft Teams while posing as an IT Service Desk from an external Microsoft 365 tenant.
- [3]
Victims are tricked into downloading and running a PowershellCleaner MSI from Azure Blob Storage; the report cites retrieval of 331.msi from filereserve.blob.core.windows.net and deployment via msiexec.
- [4]
The MSI extracts cleaner.ps1 and archive6.zip to LocalAppData, and an obfuscated PowerShell script launches a Python loader.
- [5]
A randomly named 12-character scheduled task is created via COM; it runs ss.py with pythonw.exe at logon and daily at 10:00 AM.
- [6]
The PhishLocker module collects entered passwords using a fake full-screen Windows lock screen.
- [7]
The TrafficRedirector module turns the infected device into a reverse proxy, enabling interactive control via PowerShell shells and VNC.
- [8]
The compromised device is used as a relay point between the internal LAN and external allowed services, bypassing IP allowlists by using the victim device's IP address, with authentication to internal and external services using stolen credentials.
- [10]
Observed C2 communications go to tripinupdate.net, dondermicapp.net, aroclenetapp.net and others.
- [12]
Stated preconditions for the chain: the user runs the MSI; PowerShell, Python and COM task creation are not blocked; the user enters a valid OS password into PhishLocker; C2 communication and module delivery succeed.
- [13]
Detection guidance is focused on Teams audit logs rather than email.
- [14]
Recommended mitigations: restrict external tenant Teams communication or unknown IT support; block MSI execution, Azure Blob downloads and obfuscated PowerShell; monitor and block COM Task Scheduler creation; block C2 and reverse proxy communications.
- [15]
Response guidance: change the user password and revoke all sessions; cross-check internal and external authentication from the victim IP address; investigate internal connections, PowerShell and VNC after the reverse proxy; search for other users who received the same external tenant contact.
- [17]
The writeup grades findings as: attack attempt observed (external Teams contact or MSI URL only, no execution); user action confirmed (MSI download or execution); initial execution confirmed (cleaner.ps1, Python loader, scheduled task); malware execution or authentication success confirmed; post-compromise activity confirmed (TrafficRedirector, PowerShell shell, VNC, internal service connections).
- [18]
The account used here is a dev.to summary that names Expel as the original source.
- [19]
The summary lists a related report headlined "New SynkLoader malware pushed in Microsoft Teams phishing campaign".
- [20]
A 90 to 120 second beacon interval produces roughly 720 to 960 C2 callbacks per infected device per day.
Sources
1 independent publisher whose own reporting we read for this story.
- dev.toSynkLoader Deploying Multi-Stage Modules via Teams Phishing
1 article · August 21, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
Entities
- SynkLoaderFollow
- PhishLockerFollow
- TrafficRedirectorFollow
- ExpelFollow
- dev.toFollow
- Microsoft TeamsFollow
- Azure Blob StorageFollow
- Windows Task SchedulerFollow
- PythonFollow
- PowerShellFollow