New 'SynkLoader' Malware Could Be Paving the Way for Ransomware Attacks
Want more insights like this?
Expel researcher Marcus Hutchins and colleagues found SynkLoader in a client's network on August 18, 2026, and believe it was first deployed around July 28. It spreads through Microsoft Teams messages in which the attacker poses as the target company's own IT help desk, steering users to a fake "PowerShell Cleaner" installer hosted on Azure storage.
The toolkit pairs a bundled Python environment with DLLs disguised as Microsoft runtime files, running native Windows behaviour inside Python processes to cut the signals EDR relies on. Its PhishLocker module raises a fake Windows lock screen and traps the user until they enter a password — and in SSO environments, that credential opens more than the desktop.
PhishLocker is one of seven modules; the others include a remote shell, a reverse proxy into the internal network, and desktop streaming with input takeover. A profiler module counts the size of the victim's Active Directory domain — the reconnaissance ransomware crews use to size a ransom demand.
Expel puts only low-to-medium confidence on its assessment that the toolkit belongs to a ransomware group or an initial access broker. In the meantime, verify help-desk requests through a known channel, treat unsolicited MSI installers as hostile, and if a lock screen appears unexpectedly, hit Alt+Tab — the fake one is just a window.
Source: Dark Reading