New SynkLoader Malware Targets Microsoft Teams Users with Fake Lock Screen

New SynkLoader Malware Targets Microsoft Teams Users with Fake Lock Screen

First seen 21 Aug 2026, 19:47 UTC BleepingcomputerFeeds.4Sysops 74% similarity 69.5

Article Content

Browse articles
ThreatCluster

A new malware family named SynkLoader is being distributed through phishing campaigns on Microsoft Teams, impersonating corporate IT staff to steal credentials. The malware features a convincing fake Windows lock screen designed to capture user passwords. It also includes modules for persistence, remote control, and network tunneling, suggesting potential use in ransomware operations. The malware was first compiled around July 28, 2026, and utilizes a combination of Python, PowerShell, C#, and C++. Security researchers have identified various modules, including one that attempts to obtain Windows account passwords. Users are advised to verify IT requests independently and exercise caution with unsolicited MSI file installations. Indicators of compromise (IoCs) have been provided, but hashes are unique for each infection, limiting their use for defenders.

Key Points: • SynkLoader malware is delivered via Microsoft Teams phishing messages. • The malware's fake lock screen is designed to capture Windows account passwords. • Unique module hashes for SynkLoader infections reduce the effectiveness of IoCs.

ThreatCluster AI How this analysis works

Timeline

2026-07-28
SynkLoader first compiled
Analysis indicates that SynkLoader was first compiled and distributed around this date, marking the start of its active deployment.
BleepingComputer
2026-08-21
SynkLoader identified in phishing campaigns
Security researchers reported the use of SynkLoader in phishing campaigns impersonating IT staff on Microsoft Teams.
Feeds.4Sysops

Community

Browse all →

Tracked Entities in This Story