BIGFISH TECHNOLOGY LIMITED
25 August 2026

SynkLoader Malware Targets Microsoft Teams Users in Phishing Campaign

A newly identified malware campaign is abusing Microsoft Teams to trick employees into installing SynkLoader by impersonating IT support staff. The malware can steal Windows credentials, establish persistence, collect system information, and provide attackers with remote access to compromised devices.

Phishing attacks are no longer limited to email. Attackers are increasingly targeting collaboration platforms such as Microsoft Teams, taking advantage of employees' familiarity and trust in these communication channels.

Security researchers from Expel recently identified a campaign distributing a malware family called SynkLoader. The attackers impersonate an organization's IT Help Desk and use social engineering to convince employees to install a supposedly legitimate IT utility.

What makes this campaign particularly concerning is that SynkLoader is more than a simple malware downloader. It contains multiple modules designed to gather system information, maintain persistence, steal credentials, and enable remote access.

 

What Is SynkLoader?

SynkLoader is a modular malware framework that combines multiple programming languages and components, including Python, PowerShell, C#, and C++.

Its modular architecture allows attackers to deploy different capabilities depending on the target environment.

Researchers identified several capabilities, including:

  • System Profiling – Collects information such as hostname, username, running processes, services, domain information, and Active Directory details.
  • Persistence – Creates Scheduled Tasks to maintain access to compromised systems.
  • Credential Theft – Attempts to capture Windows credentials through a fake Windows Lock Screen.
  • Remote Shell – Allows attackers to execute PowerShell commands remotely.
  • Remote Control – Provides attackers with the ability to interact with the victim's desktop, including mouse and keyboard control.
  • Traffic Redirection – Can redirect network traffic through the compromised device to reach internal services.
  • Module Monitoring – Tracks the status of deployed malware components.

 

The Attack Begins with a Fake IT Support Request

One of the most important aspects of this campaign is the use of Social Engineering.

Rather than immediately sending an obvious malicious file, attackers first establish trust by pretending to be members of the organization's IT Help Desk.

The attacker then contacts the victim through Microsoft Teams and instructs them to install a tool described as a “PowerShell Cleaner.”

The installer is distributed as an MSI file and is hosted on Microsoft Azure infrastructure, which may make the download appear more legitimate to unsuspecting users.

Once executed, the installer deploys multiple components that ultimately enable SynkLoader to operate on the compromised device.

 

Fake Windows Lock Screen Used to Steal Credentials

One of SynkLoader's most notable capabilities is a component called PhishLocker.

It displays a fake interface designed to resemble the Windows 11 Lock Screen, attempting to convince users to enter their Windows password.

The stolen credentials can then potentially be used by attackers during subsequent stages of the attack.

Researchers found that the fake Lock Screen is not actually part of Windows. Instead, it is a borderless, full-screen application designed to imitate the legitimate Windows interface.

This means users may be able to identify the deception by pressing Alt + Tab and checking whether other applications are running behind the apparent Lock Screen.

From Malware Infection to Remote Access

SynkLoader is capable of much more than credential theft.

Its Interactive Shell functionality allows attackers to send PowerShell commands to compromised systems and receive the results remotely.

Another component provides remote desktop capabilities, allowing attackers to view the victim's screen and control the mouse and keyboard.

Combined with credential theft and persistence mechanisms, these capabilities can turn an initially compromised endpoint into a potential foothold for deeper attacks against the organization.

Could SynkLoader Lead to Ransomware?

Expel researchers noted that SynkLoader's ability to collect information about the environment, including Active Directory, may indicate that the malware could be used as part of a broader intrusion operation.

Capabilities such as:

  • Credential theft
  • Persistence
  • System reconnaissance
  • Remote PowerShell access
  • Remote desktop control
  • Network traffic redirection


could potentially allow attackers to move further into an organization's network.

If attackers successfully obtain privileged credentials and gain access to critical systems, the initial compromise could potentially evolve into data theft, lateral movement, or ransomware deployment.


Why Organizations Need to Watch for Teams Phishing

The SynkLoader campaign highlights an important shift in the modern threat landscape:


The attack surface is no longer limited to email and endpoints.

Collaboration platforms such as Microsoft Teams can also become attack vectors.

Because employees regularly communicate with colleagues and IT teams through these platforms, attackers can exploit this familiarity to make malicious requests appear legitimate.

A typical attack chain could look like this:

Teams Phishing

Fake IT Support

Malicious Software Installation

SynkLoader Deployment

Persistence

System & Active Directory Reconnaissance

Credential Theft

Remote Access

Potential Lateral Movement

This means organizations need to expand their security strategy beyond traditional email protection and consider Identity, Endpoint, Collaboration Platforms, and Network Security as interconnected components.

 

How Can Organizations Reduce the Risk?

Organizations can take several steps to reduce the risk of attacks similar to the SynkLoader campaign.

  1. Verify IT Support Requests

Employees should verify unexpected requests from individuals claiming to be IT support, especially when asked to install software or execute commands.

Verification should be performed through an independent communication channel.

  1. Restrict Unauthorized Software Installation

Organizations should limit users' ability to install unauthorized applications and carefully control the execution of MSI installers.

Application control and endpoint security policies can help reduce the risk of malicious software installation.

  1. Review Microsoft Teams External Access

Security teams should regularly review Guest and External Access policies in Microsoft Teams.

Organizations should understand who can contact employees from outside the organization and whether these interactions are necessary.

  1. Monitor Suspicious Endpoint Behavior

Security monitoring should look beyond malware signatures and file hashes.

Behavioral indicators such as:

  • Suspicious PowerShell activity
  • Unexpected Scheduled Tasks
  • Unauthorized MSI installations
  • Abnormal remote connections
  • Reverse proxy activity
  • Unusual credential usage

can provide valuable signals for detecting an intrusion.

  1. Strengthen Identity Security

Organizations should continuously monitor account and credential activity for anomalies, including unusual login locations, abnormal authentication patterns, and unexpected access to critical resources.

Multi-factor authentication and strong identity controls can also reduce the impact of stolen credentials.

  1. Strengthen Cybersecurity Awareness

Security awareness training should evolve beyond traditional email phishing.

Employees should also learn how to identify:

  • Microsoft Teams Phishing
  • Fake IT Support
  • Social Engineering
  • Malicious Software Requests
  • Credential Theft Attempts

 

BigFishTec Cybersecurity Insight

The SynkLoader campaign demonstrates how modern cyberattacks can begin with something as simple as a trusted conversation.

Attackers do not always need to exploit a technical vulnerability first. Instead, they can exploit human trust through familiar communication platforms such as Microsoft Teams.

A single fraudulent IT support message could potentially lead to malware installation, credential theft, remote access, and further compromise of the corporate environment.

For this reason, organizations should move beyond a traditional “Email Phishing Protection” mindset and adopt a broader Multi-Channel Social Engineering Defense strategy covering collaboration platforms, endpoints, identities, networks, and users.

In today's threat landscape, cybersecurity is not only about protecting systems. It is also about protecting trust.