Microsoft Teams Phishing Uses SynkLoader to Steal Passwords

Teams phishing delivers new SynkLoader and fake lock screen credential stealer

Microsoft Teams phishing attacks have evolved, with cybercriminals now using a new malware toolkit called SynkLoader to steal Windows passwords. This campaign targets Microsoft 365 environments, leveraging convincing impersonation and technical sophistication to breach networks and exfiltrate credentials.

How Microsoft Teams Phishing Delivers SynkLoader Malware

This attack begins with an adversary posing as an IT helpdesk representative within Microsoft Teams. Using a company.onmicrosoft.com address, the attacker initiates a chat with the target, presenting themselves as internal support staff. The goal is to persuade the victim to install what is claimed to be a legitimate fix or utility.

The lure in these cases is a malicious MSI installer, hosted on Azure Blob Storage. This approach exploits the perceived legitimacy of Microsoft’s cloud infrastructure, making it significantly harder for employees to identify the threat. The MSI file is typically named to sound innocuous, such as “PowerShell Cleaner.” Once downloaded, it unpacks a ZIP archive and a PowerShell script into the user’s local application-data folder.

The PowerShell script is engineered to minimise its footprint on disk, launching hidden commands before starting the Python-based loader that underpins SynkLoader. By operating largely in memory, this toolkit evades many traditional endpoint defences and anti-virus tools.

  • Initial contact via Teams chat, impersonating IT helpdesk
  • Delivery of malicious MSI installer from Azure Blob Storage
  • Installation of PowerShell scripts and Python-based loader
  • Loader operates primarily in memory, minimising disk activity
  • Regular communication with rotating command and control (C2) domains

Expel researchers first identified this campaign with evidence pointing to initial construction and distribution around 28 July 2026. The threat actors use three C2 domains, rotating connections every 90 to 120 seconds, and can execute arbitrary Python code received from their servers. This live command capability gives attackers extensive control over compromised endpoints.

Technical Details: SynkLoader and PhishLocker Components

SynkLoader is a modular toolkit designed for stealth, persistence, and credential theft. The loader component gathers extensive information from the target system, including:

  • Computer name and signed-in username
  • User privilege level (such as administrator rights)
  • Running processes and installed services
  • Active Directory group membership and other organisational details

This system reconnaissance enables attackers to assess the value of the compromised machine and plan follow-on actions, such as lateral movement or privilege escalation. To maintain persistence, SynkLoader installs a scheduled task under a randomly generated name. This task executes at each user logon and at 10 a.m. local time, ensuring the loader is relaunched after restarts while blending in with legitimate system tasks.

The most innovative and concerning module within SynkLoader is PhishLocker. This component is designed to mimic the Windows lock screen with high fidelity. It pulls the current username and the real lock-screen background, creating a full-screen overlay that is nearly indistinguishable from the genuine article. When a user attempts to unlock their workstation, PhishLocker intercepts credentials entered into the fake prompt, capturing passwords for later exfiltration. This method exploits user trust in familiar workflows and can bypass multifactor authentication if the password is subsequently used elsewhere.

Key features of the SynkLoader toolkit include:

  • In-memory execution of Python code for stealth and flexibility
  • Rotating C2 infrastructure to evade IP-based blocking
  • Automated system reconnaissance and privilege assessment
  • Persistent scheduled tasks with non-descriptive names
  • PhishLocker for deceptive credential harvesting at the lock screen

Timeline and Exploitation Status

Analysis from Expel indicates that the SynkLoader toolkit first appeared in the wild around late July 2026. The initial infection vector has consistently been Microsoft Teams, with attackers leveraging the built-in trust of internal communications and the authority associated with IT helpdesk messaging.

The use of Azure Blob Storage for malware hosting was observed in all reported incidents, further reinforcing the illusion of legitimacy. As of August 2026, no evidence suggests this campaign is targeting specific sectors or geographies, but it is primarily focused on organisations with Microsoft 365 and Teams deployments.

Exploitation is ongoing, with active C2 infrastructure and new samples being identified by security researchers. The attack chain is effective against users who are unaccustomed to scrutinising internal IT requests, especially when such requests come from plausible company addresses and reference genuine support tasks.

  • First observed: 28 July 2026 (based on file timestamps and malware compilation dates)
  • Primary targets: Microsoft 365 environments, especially those using Teams
  • Delivery vector: Teams chat with IT helpdesk impersonation
  • Malware hosting: Azure Blob Storage
  • Current status: Ongoing exploitation, with active C2 rotation

Why This Matters for Organisations

This campaign demonstrates how attackers can co-opt trusted internal platforms, such as Microsoft Teams, to deliver advanced malware like SynkLoader. The use of in-memory execution, rotating C2 domains and convincing lock-screen mimics increases the risk of undetected credential theft and further compromise. Organisations with Microsoft 365 should be particularly alert to unsolicited IT requests and the deployment of unfamiliar tools from internal channels.

Actions for Organisations to Take Now

  • Review and restrict permissions for Teams chats, especially from external or newly created accounts
  • Educate employees about IT helpdesk impersonation risks within Teams
  • Monitor for unusual scheduled tasks and PowerShell activity on endpoints
  • Audit downloads from Azure Blob Storage for unapproved MSI installers

Originally reported by cybersecuritynews.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call