Skip to content

Build1 publisherNot yet confirmed elsewhere3 min readPublished

SynkLoader: the Teams help-desk lure now ships with a reverse proxy attached

Expel's writeup describes a chain with no exploit in it: an external-tenant Teams message, an MSI from Azure Blob, a COM-made scheduled task, a fake lock screen, and a relay into the LAN.

The Engineer · Build desk

How we use AISend a correction

What happened

  • Expel documented a multi-stage intrusion kit it calls SynkLoader in a report dated 20 August 2026 and rated high severity.
  • First contact is a Teams message from an external Microsoft 365 tenant, with the sender posing as the IT service desk.
  • The user is talked into running a PowershellCleaner MSI, retrieved as 331.msi from an Azure Blob host and launched through msiexec.
  • The installer drops cleaner.ps1 and a zip into LocalAppData, and a COM-created task with a random 12-character name runs ss.py under pythonw.exe.
  • Two modules follow: PhishLocker, which harvests the password via a full-screen fake lock screen, and TrafficRedirector, which opens PowerShell shells and VNC over a reverse proxy.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • exposure With the host relaying traffic, the credentials arrive at internal and external services from an employee's own address, so IP allowlists vouch for the intruder instead of stopping it.
  • constraint Nothing in the initial approach passes through the mail gateway, so the evidence that matters sits in Teams audit logs, a data set most SOCs neither own nor tune.
  • decision Only one of the recommended controls acts before the installer runs, which turns this into a policy argument about external-tenant chat rather than a tooling purchase.
  • precedent Because payloads are handed out selectively, an indicator sweep that finds no lock-screen artefacts cannot be reported as a clean host.

Expel lists the preconditions for this chain plainly, and not one of them is a software flaw: the user has to run the MSI, PowerShell and Python and COM task creation have to be unblocked, the user has to type a valid Windows password into the fake lock screen, and C2 delivery has to succeed [12]. There are no CVEs in the writeup and no attributed group [16]. Everything that makes SynkLoader work is a configuration somebody chose, or declined to make.

The traffic side is not quiet if you measure it. A beacon with 90 to 120 second jitter [11] works out to roughly 720 to 960 callbacks per device per day [20]. It survives on destination rather than volume, and one of the three domains Expel names is tripinupdate.net, which is the shape of a string a network reviewer skims past [10].

Module delivery is selective, from multiple C2 servers [9]. Two infected hosts in the same organisation need not be carrying the same payloads, so a sweep for the PhishLocker fake lock screen [6] can come back clean on a machine that is already relaying traffic outward [7]. The stage common to every variant is the cheaper thing to hunt: a randomly named 12-character scheduled task, created through COM, running ss.py under pythonw.exe at logon and again at 10:00 each day [5].

The relay is also why a password reset does not close the ticket. Expel's response sequence puts credential rotation and session revocation alongside cross-checking internal and external authentication from the victim's IP address, investigating the PowerShell and VNC activity that follows the proxy, and hunting for other users contacted by the same external tenant [15]. That last step is the one that decides whether this was one employee or a mailbox-wide sweep of the org.

Of the four mitigations listed, three are blocks applied after the lure lands: MSI execution, Azure Blob downloads and obfuscated PowerShell; COM Task Scheduler creation; C2 and reverse proxy egress [14]. Only restricting external-tenant Teams contact acts before msiexec runs [14], and Expel points the detection work at Teams audit logs rather than email [13], which is a different log source with a different owner in most shops.

Read the confidence ladder in the report before you escalate: it separates an external Teams contact or MSI URL with no execution from confirmed user action, confirmed loader and task creation, and confirmed post-compromise proxy and VNC activity [17]. That distinction is doing real work here, because the first rung will be the most common finding and the cheapest to close. One caveat on sourcing: this account is a dev.to summary crediting Expel as the original [18], with a second writeup listed alongside it on the same campaign [19] rather than an independent confirmation of the artefacts.

What to watch

  • Whether Microsoft tightens defaults or adds first-contact friction for chats from unmanaged external tenants, which is the only control that bites before msiexec runs.
  • Whether a second responder publishes overlapping C2 or Azure Blob infrastructure, which would separate one crew from a kit in circulation.
  • Whether any affected organisation confirms authentication to external SaaS from a victim IP, the allowlist-bypass step that is hardest to see after the fact.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence58
Adoption20
Hype gap+14
Incentives62
Confidence55
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Expel published a report titled "SynkLoader: when you throw in everything but the kitchen sink" dated 2026-08-20, rated severity high.

    ReportedSupportedView cited source
  2. [2]

    Attackers contact victims on Microsoft Teams while posing as an IT Service Desk from an external Microsoft 365 tenant.

    ReportedSupportedView cited source
  3. [3]

    Victims are tricked into downloading and running a PowershellCleaner MSI from Azure Blob Storage; the report cites retrieval of 331.msi from filereserve.blob.core.windows.net and deployment via msiexec.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. dev.to

    1 article · August 21, 2026

    SynkLoader Deploying Multi-Stage Modules via Teams Phishing

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

  • Teams help-desk social engineeringFollow
  • Reverse proxy relay and IP allowlist bypassFollow
  • COM-based persistence telemetry gapsFollow
  • Modular loader and C2 tradecraftFollow
  • Credential theft via fake lock screenFollow
  • Living Off Trusted Cloud ServicesFollow
Loading related stories