SynkLoader malware spreads through fake Microsoft Teams IT help-desk messages and steals Windows passwords

Attackers are using Microsoft Teams messages that pretend to come from a company IT help desk to trick employees into installing SynkLoader malware. Expel says the campaign delivers a fake "PowerShell Cleaner" MSI from Microsoft Azure, then deploys modules for host profiling, persistence, remote command execution, desktop control, traffic tunneling, and a fake Windows lock screen called PhishLocker that captures the user's password. The malware appears to have first been compiled and distributed around July 28, 2026 and may support follow-on ransomware activity.
Why it matters: Organizations using Microsoft Teams should treat unsolicited IT-support messages and software installs as high risk, because one mistaken install can give attackers credentials and remote access inside the network. Defenders should warn users, review Teams-based social-engineering controls, hunt for the MSI and related scripts, and check whether any affected users entered passwords into a fake lock screen.

Sources

New SynkLoader malware pushed in Microsoft Teams phishing campaign
Bill Toulas 2026.08.21 100% relevant
This article establishes a distinct new malware and delivery campaign centered on SynkLoader, with specific Teams impersonation tactics, malware components, and credential-theft behavior rather than just a generic trend.
← Back to all stories