Microsoft Teams phishing is again being used as a doorway to deliver a malware family called SynkLoader.
Microsoft Teams Phishing Deploys New SynkLoader MalwareMetadata from the incomplete conversation showed an account using a company.onmicrosoft.com address contacting the target as an IT service desk.
Fake Lock Screen Steals PasswordsThe most concerning add-on is PhishLocker, a component built to resemble the Windows lock screen.
The screen is not a real lock screen, and the password does not need to be correct for the user to move past it.
Security teams should review external Teams communications, investigate unapproved MSI downloads and new scheduled tasks, and watch for suspicious in-memory PowerShell activity.
Microsoft Teams phishing is again being used as a doorway to deliver a malware family called SynkLoader.
The campaign relies on a familiar social-engineering trick: an attacker poses as an IT helpdesk worker and persuades an employee to install what appears to be a useful fix.
It deploys a layered toolkit that hides much of its activity in memory, gathers details about the victim’s Windows system, and maintains a channel back to the operators. That gives a Teams chat the potential to become a serious corporate network intrusion.
Analysts at Expel identified the malware during an investigation. The components appeared new, with compilation and file timestamps indicating the toolkit was first built and distributed around July 28, 2026.
An excerpt from cleaner1.ps1 (Source – Expel)
Expel said in a report shared with Cyber Security News (CSN) that the recent Teams helpdesk impersonation campaigns show how criminals can borrow the authority of internal support staff, then turn a seemingly routine request into malware delivery.
Microsoft Teams Phishing Deploys New SynkLoader Malware
Metadata from the incomplete conversation showed an account using a company.onmicrosoft.com address contacting the target as an IT service desk.
The attacker convinced the employee to download an MSI file from Azure Blob Storage, lending the download an appearance of legitimacy.
That MSI presented itself as “PowerShell Cleaner” and unpacked a ZIP archive plus a PowerShell script into the user’s local application-data folder. The script launches hidden PowerShell commands before starting the Python-based loader and limiting later-stage disk activity.
It ships a small Python environment, scripts, compiled libraries, and DLL components that work together to run commands in memory. The main loader rotates among three control domains, checks in every 90 to 120 seconds, and can execute Python code returned by the server.
A re-creation of the C2 beacon function (Source – Expel)
It also collects the computer name, signed-in username, privilege level, running processes, services, Active Directory details, and other system information. This reconnaissance helps operators judge a machine’s value, as in Teams malware delivery cases.
The toolkit also installs a scheduled task under a random name. It runs at logon and at 10 a.m. local time, restoring the loader after a restart while avoiding obvious task-creation commands.
Fake Lock Screen Steals Passwords
The most concerning add-on is PhishLocker, a component built to resemble the Windows lock screen. It retrieves the current username and lock-screen background, then opens a full-screen window designed to look like a genuine Windows 11 password prompt.
The goal is to collect the user’s raw Windows password. The screen is not a real lock screen, and the password does not need to be correct for the user to move past it.
Still, a captured password can be more useful than a stolen password hash, especially in organisations using single sign-on. That creates a wider opportunity to move through internal services with legitimate-looking credentials. A TrafficRedirector module extends that risk by acting as a reverse proxy through the infected device.
It can let operators reach internal network services or connect to internet services using the victim’s corporate IP address, reducing the warning signs associated with unfamiliar locations. Similar Teams credential phishing activity has made password theft a central concern.
The researchers also received modules for a remote PowerShell shell and a VNC-based remote-control function. The actor tried to run reconnaissance commands against Expel’s emulated environment before recognising it was not a real corporate network.
The scheduled task with a random name and two triggers defined (Source – Expel)
Researchers assessed, with low to medium confidence, that the toolkit could belong to a ransomware group or an access broker.
Employees should verify unexpected support messages through a known internal channel before installing anything, even when the request arrives in Teams.
Security teams should review external Teams communications, investigate unapproved MSI downloads and new scheduled tasks, and watch for suspicious in-memory PowerShell activity.
These checks complement lessons from fake Teams update operations, where trusted branding was likewise used to mask remote access.
They should also block or closely inspect network traffic involving the listed command-and-control infrastructure and preserve relevant Teams audit records for investigation.
Indicators of compromise (IoCs):-
Type Indicator Description URL https://filereserve.blob.core.windows.net/vgnghuyk/331331.msi Initial installer URL sent through Teams SHA-256 151D2A7F52F047638CA8AD80C859C6BFE04D7510FB10933817FA0E3BA5D07A11 Initial installer SHA-256 80F08360BA768B152B71ABB1CAB557F552A13DE18C83FE8E6396A197FEEC9185 First-stage payload SHA-256 209F69A6CA859F05C954096B30391A43FDA33C9ED264DFDCCF806697F04B06A8 ZIP archive containing loader SHA-256 D150C70D2732DF17AA77991B9EBF4C896F044445E900978581D9598DFA5DC98C Main loader SHA-256 61F961CFEBDF9967844526649B4B75BBA5B1B83210B70AA1BFFE3F64E6AC3112 PowerShell executor DLL SHA-256 8207D8D949530EA063FFD5D47EE81B74BF718EC0A4755E2349E6AF9B91E92DC1 DLL loader SHA-256 C4ACDA412774C292F0DB5D64467A2DD09282CDEA43C41967E8BF90F6298ACCF3 Profiling module loader SHA-256 63622C1DDB3E2A9F11CAC192E13AC7494F558516B19D5D8F140F6D0D4D38EA84 Persistence module loader SHA-256 A335E75B78B601EBC5C258975D95FD79AA21F836FC6B79D82E9A22C596133F07 Fake lock screen loader SHA-256 0428FBDEFA8DDA10CE8FC12B1B516641E83CD5088388168E3F1A0BE1432B4077 Persistence module DLL SHA-256 CB1C657F74B9E57F5E81126179128E8DB949D1D4196BE9DCB890341E222FD384 Fake lock screen DLL Domain neversoftmain.net SynkLoader command-and-control domain Domain rootfarmapp.net SynkLoader command-and-control domain Domain tripinupdate.net SynkLoader command-and-control domain Domain dondermicapp.net TrafficRedirector command-and-control domain Domain aroclenetapp.net VNC module command-and-control domain
Note: IP addresses and domains are intentionally defanged (e.g., [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC