All incidents

SynkLoader malware campaign uses fake Teams and lock screens to steal credentials

malwareopenAug 24, 2026 — Aug 28, 2026
SynkLoader malware campaign uses fake Teams and lock screens to steal credentials

RESEARCHERS at Expel have identified a new malware family called SynkLoader that uses fabricated Microsoft Teams alerts and a counterfeit Windows lock screen to harvest corporate credentials.

The campaign, first observed on 24 August 2026, targets enterprises by posing as IT support and delivering a malicious file presented as a routine maintenance utility.

SynkLoader begins with a phishing email that mimics an internal IT notice, attaching a ZIP archive containing a signed executable that pretends to be a network diagnostics tool.

When executed, the payload launches a series of scripts written in PowerShell, Python and JavaScript to evade signature detection, creates a scheduled task for persistence, and opens a reverse proxy tunnel to attacker-controlled infrastructure.

The malware also drops a malicious DLL that mimics the legitimate Windows lock screen module; when a user attempts to unlock their workstation, the DLL captures the entered username and password and transmits them over the established proxy.

In addition, SynkLoader profiles the host, collecting information such as running processes, installed applications and network shares to aid further lateral movement.

Expel’s telemetry shows that SynkLoader was active between 24 and 28 August 2026, with several hundred infection attempts recorded across various sectors.

While no specific threat actor has been linked to the campaign, the malware’s design includes modules commonly seen in ransomware preparation phases, such as system profiling and credential harvesting.

Organisations should reinforce user awareness training to help staff recognise unsolicited Teams messages that claim to come from IT support, especially when they contain unexpected attachments.

Enforcing multi-factor authentication on all privileged accounts reduces the value of stolen credentials, while application control policies can block the execution of unapproved binaries from temporary folders.

Security teams ought to monitor for newly created scheduled tasks that point to scripts in user profile directories and for outbound connections to unfamiliar IP ranges that resemble reverse proxy traffic.

Keeping endpoint detection and response tools tuned to detect in-memory execution of PowerShell and Python scripts will help catch the malware before it can establish a foothold.

Intelligence briefing updated Aug 28, 2026

Root sourceexpel.com
Timeline Coverage

Swipe to explore timeline