securityonline.info 8/28/2026, 10:10:35 AM · external

New SynkLoader malware uses fake Teams IT support to breach firms

New SynkLoader malware uses fake Teams IT support to breach firms
Developing story malware 2 articles tracked
SynkLoader malware campaign uses fake Teams and lock screens to steal credentials
CyberSIXT Evidence Panel
Primary Source expel.com

THE article discusses the detection of a new malware, SynkLoader, identified by Expel security researchers. This malware targets corporate networks using a sophisticated attack chain that employs social engineering via Microsoft Teams. Attackers impersonate IT support to deliver malicious files disguised as maintenance utilities. SynkLoader executes various programming languages to avoid detection, establishes backconnect proxies, and utilizes a fake lock screen to steal credentials.

The malware maintains persistence through scheduled tasks and employs a reverse proxy to tunnel into corporate networks. Recommendations for defense include employee training, blocking unapproved downloads, and implementing multi-factor authentication.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline