Security researchers have identified a previously unknown malware family called SynkLoader, which is being distributed through targeted Microsoft Teams phishing campaigns.
The attackers impersonate the victim organization's IT help desk and convince employees to install a fake “PowerShell Cleaner” application. The malicious MSI is hosted on Microsoft Azure, making the download appear more legitimate.
The malware is particularly dangerous because it is not limited to credential theft. SynkLoader provides attackers with persistence, reconnaissance, remote shell access, reverse-proxy functionality and remote desktop control.
Key Highlights
- Malware: SynkLoader
- Initial access: Microsoft Teams phishing
- Impersonation: Corporate IT/help desk
- Delivery: Malicious MSI
- Fake application: PowerShell Cleaner
- Hosting: Microsoft Azure
- First observed compilation/distribution: Around July 28, 2026
- Components use PowerShell, Python, C# and C++
- Credential theft through a fake Windows lock screen
- Scheduled-task persistence
- Reverse-proxy functionality
- Remote PowerShell shell
- VNC-based remote desktop control
- Active Directory reconnaissance
- Potential connection to ransomware operations.
Microsoft Teams Phishing
The campaign begins with attackers impersonating the victim organization's IT support team.
The victim is instructed to install a supposedly legitimate utility called:
PowerShell Cleaner
The application is delivered as an MSI installer hosted on Microsoft Azure.
Using legitimate cloud infrastructure for malware delivery can make the download appear more trustworthy and may complicate basic reputation-based detection.
SynkLoader Multi-Language Architecture
SynkLoader stands out because it combines multiple programming languages.
Researchers observed components written in:
PowerShell Python C# C++
Some modules can combine as many as three of these languages.
This multi-language architecture can make analysis and detection more challenging because defenders may need to correlate activity across multiple interpreters and runtimes.
Multi-Stage Installation
The MSI installer extracts:
cleaner.ps1
along with a ZIP archive containing:
- Python framework
- Malicious Python script
- Precompiled Python libraries
- Fake Microsoft runtime DLLs
The combination creates a portable execution environment that allows the malware to operate without relying entirely on software already installed on the victim's system.
SynkLoader Modules
Expel identified several modules associated with SynkLoader.
1. System Profiler
Collects information including:
- Hostname
- Username
- Privilege level
- Running processes
- Services
- Domain information
- Active Directory computer count
This information helps attackers determine the characteristics and size of the compromised environment.
2. Persistence Module
The malware creates a randomly named scheduled task.
The task launches SynkLoader:
- At user logon
- Daily at approximately 10:00 AM
Scheduled-task persistence allows the malware to survive system restarts and maintain access after the initial execution.
3. PhishLocker
The most notable module is PhishLocker.
It displays a convincing fake Windows 11 lock screen designed to capture the victim's Windows account password.
The stolen password can then potentially be combined with SynkLoader's tunneling functionality to access internal corporate resources from the compromised machine.
Fake Windows Lock Screen
The fake lock screen is implemented as a full-screen, borderless GUI application.
Although visually convincing, researchers noted a simple way to identify it:
Alt + Tab can expose the legitimate windows running behind the fake lock screen.
Users who unexpectedly encounter a Windows lock screen should therefore avoid entering credentials and instead verify whether the screen behaves like the genuine Windows security interface.
TrafficRedirector
SynkLoader includes a TrafficRedirector module that creates a reverse proxy.
This allows attackers to:
- Reach internal network services through the infected system.
- Route internet traffic through the compromised computer.
- Potentially bypass IP allow-list restrictions.
This functionality significantly increases the value of the compromised endpoint as an access point into the corporate network.
Interactive Shell
The Interactive Shell / RAT module provides remote command execution.
Attackers can remotely execute PowerShell commands and receive the command output.
This provides hands-on-keyboard capabilities and allows operators to perform additional reconnaissance or deploy further tools.
StreamMaster VNC
The StreamMaster module provides VNC-style remote desktop functionality.
It allows the attacker to:
- View the victim's desktop.
- Control the mouse.
- Control the keyboard.
- Interact with the active user session.
This enables attackers to operate the compromised system interactively rather than relying exclusively on command-line access.
Potential Ransomware Connection
Researchers observed that SynkLoader performs reconnaissance focused on determining the size of the Active Directory environment.
This behavior is consistent with attackers attempting to understand the potential scale of an enterprise compromise.
Expel's researcher assessed that the malware is likely being used in ransomware operations, although the article does not establish a specific ransomware group behind the campaign.
Hands-on-Keyboard Activity
Expel created an emulator for SynkLoader's reverse-shell module to verify whether the activity represented interactive attacker behavior.
During testing, the threat actor attempted several profiling commands before recognizing that the environment was a honeypot and disconnecting.
This indicates that the malware is being operated interactively rather than functioning solely as an automated bot.
Detection and Hunting Opportunities
Security teams should monitor for:
- Microsoft Teams messages impersonating IT support.
- Unexpected requests to install software.
- MSI files received through Teams-related workflows.
- MSI installers downloaded from Azure-hosted locations.
-
cleaner.ps1. - PowerShell launched by MSI installers.
- Python execution from unusual directories.
- Python processes launching additional binaries.
- Fake Microsoft runtime DLLs.
- Randomly named scheduled tasks.
- Scheduled tasks executing at user logon.
- Scheduled tasks executing around 10:00 AM.
- Credential prompts presented by unknown applications.
- Full-screen borderless GUI applications.
- Reverse-proxy behavior from employee endpoints.
- Unexpected inbound connections through workstations.
- Remote PowerShell execution.
- VNC activity from unexpected processes.
- Active Directory enumeration from newly compromised endpoints.
Recommended Detection Logic
A high-confidence detection chain could correlate:
Microsoft Teams Phishing + MSI Download + PowerShell Execution + Python Execution + Scheduled Task Creation + AD Reconnaissance
Another useful behavioral correlation is:
Unknown GUI Application + Full-Screen / Borderless Window + Credential Collection + Network Activity
Recommended Mitigations
- Verify unexpected IT-support requests through an independent communication channel.
- Do not install unsolicited MSI files received through Teams.
- Restrict software installation privileges for standard users.
- Monitor MSI execution from user-writable directories.
- Detect PowerShell execution initiated by MSI installers.
- Monitor Python execution from temporary or unusual directories.
- Audit newly created scheduled tasks.
- Monitor scheduled tasks that launch at logon.
- Protect Windows credentials with phishing-resistant authentication.
- Monitor reverse-proxy behavior from endpoints.
- Restrict unnecessary inbound connections to workstations.
- Monitor unexpected VNC/RAT activity.
- Investigate unusual Active Directory enumeration.
- Segment critical systems and administrative networks.
- Correlate Teams, endpoint, identity and network telemetry.
Threat Assessment
SynkLoader represents a High-severity enterprise threat because it combines initial access, credential theft, persistence, reconnaissance and remote-control capabilities in a single modular framework.
The fake Windows lock-screen component is particularly dangerous because stolen Windows credentials can potentially be reused for lateral movement.
The reverse-proxy capability further increases the risk by allowing attackers to use a compromised workstation as a bridge into internal resources.
Indicators of Compromise
Url:- https://filereserve.blob.core.windows[.]net/vgnghuyk/331/331.msi
File Hashes:
- 151d2a7f52f047638ca8ad80c859c6bfe04d7510fb10933817fa0e3ba5d07a11
- 80f08360ba768b152b71abb1cab557f552a13de18c83fe8e6396a197feec9185
- 209F69A6CA859F05C954096B30391A43FDA33C9ED264DFDCCF806697F04B06A8
- D150C70D2732DF17AA77991B9EBF4C896F044445E900978581D9598DFA5DC98C
- 61F961CFEBDF9967844526649B4B75BBA5B1B83210B70AA1BFFE3F64E6AC3112
- 8207D8D949530EA063FFD5D47EE81B74BF718EC0A4755E2349E6AF9B91E92DC1
- C4ACDA412774C292F0DB5D64467A2DD09282CDEA43C41967E8BF90F6298ACCF3
- 63622C1DDB3E2A9F11CAC192E13AC7494F558516B19D5D8F140F6D0D4D38EA84
- A335E75B78B601EBC5C258975D95FD79AA21F836FC6B79D82E9A22C596133F07
- 0428FBDEFA8DDA10CE8FC12B1B516641E83CD5088388168E3F1A0BE1432B4077
- CB1C657F74B9E57F5E81126179128E8DB949D1D4196BE9DCB890341E222FD384
Domains:
- neversoftmain[.]net
- rootfarmapp[.]net
- tripinupdate[.]net
- dondermicapp[.]net
- aroclenetapp[.]net
Conclusion
SynkLoader demonstrates how Microsoft Teams-based social engineering can evolve into a full enterprise intrusion.
Organizations should treat unexpected IT-support requests and software installations delivered through collaboration platforms as high-risk events.
Detection should focus on the complete attack chain—Teams phishing → MSI execution → PowerShell/Python → persistence → credential theft → AD reconnaissance → remote access—rather than relying only on malware hashes.