<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

New 'SynkLoader' Malware Could Be Paving the Way for Ransomware Attacks

SynkLoader spreads through Microsoft Teams phishing and fakes a Windows lock screen to steal passwords. Expel links it to ransomware with low-to-medium confidence.
Content Team

Expel researcher Marcus Hutchins and colleagues found SynkLoader in a client's network on August 18, 2026, and believe it was first deployed around July 28. It spreads through Microsoft Teams messages in which the attacker poses as the target company's own IT help desk, steering users to a fake "PowerShell Cleaner" installer hosted on Azure storage.

The toolkit pairs a bundled Python environment with DLLs disguised as Microsoft runtime files, running native Windows behaviour inside Python processes to cut the signals EDR relies on. Its PhishLocker module raises a fake Windows lock screen and traps the user until they enter a password — and in SSO environments, that credential opens more than the desktop.

PhishLocker is one of seven modules; the others include a remote shell, a reverse proxy into the internal network, and desktop streaming with input takeover. A profiler module counts the size of the victim's Active Directory domain — the reconnaissance ransomware crews use to size a ransom demand.

Expel puts only low-to-medium confidence on its assessment that the toolkit belongs to a ransomware group or an initial access broker. In the meantime, verify help-desk requests through a known channel, treat unsolicited MSI installers as hostile, and if a lock screen appears unexpectedly, hit Alt+Tab — the fake one is just a window.

Source: Dark Reading

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo