New SynkLoader malware pushed in Microsoft Teams phishing campaign
Malware family SynkLoader being distributed via fake lock screen in Microsoft Teams phishing campaigns to steal credentials.
Intelligence analysis by Qwen 2.5 (3B)

SynkLoader malware is being used in new phishing attacks targeting Microsoft Teams users, stealing login information and potentially gaining access to corporate environments.
Malware called SynkLoader is tricking people into giving up their passwords by pretending to be a fake lock screen on Microsoft Teams. This lets the bad guys get into computers and steal important information.
Analysis
SynkLoader Malware Overview
SynkLoader is a previously unknown malware family that has been detected in recent Microsoft Teams phishing campaigns. The attacks involve impersonating IT help desks and tricking users into downloading fake executables.
Phishing Tactics
The attackers use convincing fake lock screens to capture login credentials, bypassing security measures like IP allow-lists. They also deploy a reverse proxy module to route internet traffic through the infected device.
Persistence Mechanism
SynkLoader employs a persistence module that creates scheduled tasks for regular execution at user logon and daily intervals. This ensures the malware remains active even after users close their sessions.
Analysis of SynkLoader Modules
Expel's security researchers identified several modules within SynkLoader, including:
- System Profiler: Collects detailed information about the breached environment.
- Persistence Module: Sets up a scheduled task for regular execution.
- PhishLocker: Displays a fake Windows lock screen to capture login credentials.
- TrafficRedirector: Creates a reverse proxy to route internet traffic through the infected device.
- Interactive Shell (RAT): Allows remote command execution and session control.
- StreamMaster (VNC): Enables remote desktop access.
Implications for Security
The use of SynkLoader in phishing campaigns underscores the importance of independent verification of IT requests, especially when dealing with unexpected lock screens. Organizations should implement robust security measures such as multi-factor authentication and regular security training to protect against such attacks.
Key points
- SynkLoader is a new malware family targeting Microsoft Teams users
- Phishing attacks involve fake lock screens and other sophisticated tactics
- Persistence mechanisms ensure the malware remains active even after sessions are closed
By improving security training for employees, organizations can better spot phishing attempts like this one and avoid falling victim to them.
If attackers continue to use sophisticated tactics like SynkLoader, it may become harder for companies to prevent data breaches. This could lead to more serious consequences such as financial losses or reputational damage.


