SynkLoader is a newly identified malware family spread through Microsoft Teams phishing campaigns that impersonate a company’s IT help desk and trick victims into installing a fake “PowerShell Cleaner” MSI from Microsoft Azure. It uses a fake Windows lock screen to steal credentials and can deploy modules for persistence, traffic redirection, remote shell access, and desktop control, with activity suggesting possible ransomware preparation. #SynkLoader #MicrosoftTeams #PhishLocker #PowerShellCleaner #Expel #MarcusHutchins
Keypoints
- SynkLoader is distributed through Microsoft Teams phishing lures.
- Attackers impersonate the target company’s IT help desk.
- Victims are tricked into installing a fake “PowerShell Cleaner” MSI from Azure.
- PhishLocker shows a fake Windows lock screen to steal passwords.
- The malware includes modules for persistence, tunneling, remote shell access, and VNC control.