SynkLoader Malware Spreads Through Microsoft Teams Phishing and Steals Windows Passwords
Brief
A previously undocumented malware loader, dubbed SynkLoader, that combines Python, C#, and native C++ components to evade detection, steal Windows credentials, and enable deep network access.
First spotted on August 18, 2026, during an EDR alert triggered by a suspicious scheduled task, the malware appears to have been compiled around July 28, 2026, and shows hallmarks of ransomware or initial-access-broker tooling.
The infection began with a Microsoft Teams message from an attacker posing as “IT Service Desk ,” using a spoofed @company. onmicrosoft. com address to appear legitimate.
SynkLoader Malware Spreads Through Microsoft Teams
The impersonator convinced the target to download an MSI installer, disguised as a “PowerShell Cleaner,” from an Azure Blob Storage URL, lending the payload false credibility by leveraging Microsoft’s own infrastructure.
