← Back to feed
PhishingEmerging1 sourceAug 24, 2026 · 09:46via CyberPress

SynkLoader Malware Spreads Through Microsoft Teams Phishing and Steals Windows Passwords

Brief

A previously undocumented malware loader, dubbed SynkLoader, that combines Python, C#, and native C++ components to evade detection, steal Windows credentials, and enable deep network access.

First spotted on August 18, 2026, during an EDR alert triggered by a suspicious scheduled task, the malware appears to have been compiled around July 28, 2026, and shows hallmarks of ransomware or initial-access-broker tooling.

The infection began with a Microsoft Teams message from an attacker posing as “IT Service Desk ,” using a spoofed @company. onmicrosoft. com address to appear legitimate.

SynkLoader Malware Spreads Through Microsoft Teams

The impersonator convinced the target to download an MSI installer, disguised as a “PowerShell Cleaner,” from an Azure Blob Storage URL, lending the payload false credibility by leveraging Microsoft’s own infrastructure.

Read more on CyberPress