Mastodon Skip to content
pulseofnations. Real News. Global Impact.
live markets
S&P 5007,674.37▲ 2.20%NASDAQ26,180.46▲ 1.33%DOW53,277.01▲ 2.02%GOLD4,706.40▲ 16.31%WTI85.33▼ 7.44%BRENT92.68▼ 7.96%EUR/USD1.1688▲ 2.73%USD/JPY158.82▼ 3.06%DXY98.80▼ 2.60%BTC$77,412▼ 0.40%ETH$2,446▲ 0.00%SOL$94.67▼ 2.30%TOTAL CRYPTO$2.62T▼ 2.17%

SynkLoader Malware Hits Teams With Fake Lock Screen

New modular malware family spreads via Microsoft Teams phishing, uses a convincing fake lock screen to steal Windows credentials and deploy network tunneling tools

Partner Surfshark VPN

A previously unknown malware family dubbed SynkLoader is being deployed in Microsoft Teams phishing campaigns that impersonate internal IT helpdesks, stealing Windows credentials through a sophisticated fake lock screen before deploying network tunneling tools for lateral movement.

The discovery was made by Marcus Hutchins, a security researcher at Expel, who reverse-engineered the malware and emulated its command-and-control protocol to lure threat actors into a fake network environment. The investigation began on August 18, 2026.

The attack begins with a Teams message from an external Microsoft 365 tenant posing as the target company IT helpdesk. The victim is directed to download a fake PowerShell Cleaner MSI installer hosted on Microsoft Azure, lending the payload a veneer of legitimacy. Once executed, the installer extracts a PowerShell script alongside a ZIP archive containing a multi-language malware framework.

Seven Modules, Four Languages

SynkLoader earned its name from its unusual engineering approach, combining Python, PowerShell, C#, and C++ – sometimes blending three languages within a single module. This technique appears designed to frustrate signature-based detection tools. After setting up a honeypot connected to the attacker C2 infrastructure, Expel identified seven distinct modules: System Profiler, Persistence Module, PhishLocker, TrafficRedirector, Interactive Shell, StreamMaster, and Module Status Script.

The Persistence Module creates a randomly named scheduled task launching the malware at user logon and daily at 10 a.m. The TrafficRedirector module builds a reverse proxy allowing attackers to route traffic through the infected machine, bypassing IP allow-list restrictions on corporate networks. StreamMaster enables full remote desktop control, while the Interactive Shell provides a command-and-control RAT capability.

The Lock Screen That Isn t

The most novel component is PhishLocker, which renders a full-screen GUI application designed to closely mimic the Windows 11 lock screen. It reads the current user username via GetUserName and loads the lock screen background image. When the victim enters their password, it is captured and relayed to the attackers.

However, the fake screen has telltale weaknesses. Pressing Alt+Tab exposes the full application window, and the fake prompt does not actually validate the entered password – any string will dismiss it. Hutchins noted this is the first time he has observed this lock-screen phishing technique used locally by malware, as prior instances were limited to browser-based attacks from over a decade ago.

Based on SynkLoader focus on profiling Active Directory environment size – specifically counting computers in the domain – Hutchins assessed the malware is likely deployed as a precursor to ransomware operations. Expel emulator lured the threat actor into a hands-on-keyboard session, during which the attacker ran profiling commands before realizing the network was artificial and disconnecting.

SourcesBleepingComputer; Expel; Marcus Hutchins
React to this dispatch
Share this dispatch X WhatsApp Bluesky Report an error
Written by

Founder and editor of Pulse of Nations, an independent wire service covering war, geopolitics, markets and technology.

discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Next dispatch Zero-Click Attack Steals Grok Chat History via Encrypted Payloads Read →