SynkLoader Microsoft Teams help-desk phishing campaign
Campaign
Summary
Hide ▲
Show ▼
The SynkLoader campaign is using Microsoft Teams help-desk impersonation and a fake PowerShell Cleaner MSI to push victims into a credential-theft chain that can open corporate environments from infected devices. The malware was first compiled and distributed around July 28, 2026, and it combines fake login prompts with access modules for reverse proxying, remote shell, and VNC control. The operation is aimed at corporate users and is designed to collect passwords, expand internal access, and support follow-on intrusion activity. The module mix and Active Directory profiling suggest a campaign built for deeper post-compromise operations, not just a single credential grab.
Related Happenings
SLEEPWALKER Windows backdoor reverse engineering with YARA and PowerShell detection
Technical Analysis
H score23
First: 26.08.2026 10:12
Last: 26.08.2026 10:12
Sources 1
About this happening:
Researchers documented SLEEPWALKER, a previously unreported Windows backdoor that stays inert until a crafted packet arrives, expanding the set of stealthy post-compromise...
SLEEPWALKER Windows backdoor reverse engineering with YARA and PowerShell detection
Technical AnalysisAbout this happening: Researchers documented SLEEPWALKER, a previously unreported Windows backdoor that stays inert until a crafted packet arrives, expanding the set of stealthy post-compromise...
SynkLoader malware distribution via Microsoft Teams phishing
Malware Activity
H score26
First: 21.08.2026 21:01
Last: 21.08.2026 21:01
Sources 1
How related:
A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen.
About this happening:
The SynkLoader malware family is being pushed through Microsoft Teams phishing to steal credentials with a fake Windows lock screen, giving attackers remote access...
SynkLoader malware distribution via Microsoft Teams phishing
Malware ActivityHow related: A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen.
About this happening: The SynkLoader malware family is being pushed through Microsoft Teams phishing to steal credentials with a fake Windows lock screen, giving attackers remote access...
TWINLOOT Microsoft services C2 implant activity
Malware Activity
H score29
First: 18.08.2026 15:38
Last: 18.08.2026 15:38
Sources 1
About this happening:
TWINLOOT is a newly disclosed Python implant that hides command-and-control inside Microsoft services, increasing the odds that malicious traffic blends into normal en...
TWINLOOT Microsoft services C2 implant activity
Malware ActivityAbout this happening: TWINLOOT is a newly disclosed Python implant that hides command-and-control inside Microsoft services, increasing the odds that malicious traffic blends into normal en...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor Meta
H score37
First: 09.07.2026 17:39
Last: 09.07.2026 17:39
Sources 1
About this happening:
Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor MetaAbout this happening: Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
Y2K Operators Millenium RAT social-engineering distribution campaign
Campaign
H score73
First: 29.06.2026 17:30
Last: 29.06.2026 17:30
Sources 1
About this happening:
The Y2K Operators are running a social-engineering distribution campaign that spreads Millenium RAT through booby-trapped downloads, exposing users to remote compr...
Y2K Operators Millenium RAT social-engineering distribution campaign
CampaignAbout this happening: The Y2K Operators are running a social-engineering distribution campaign that spreads Millenium RAT through booby-trapped downloads, exposing users to remote compr...
Timeline
-
21.08.2026 21:01 1 articles · 13d ago
SynkLoader is distributed through Microsoft Teams help-desk phishing
Campaign Scope UpdateCompile dates and file timestamps indicate SynkLoader was first compiled and distributed around July 28, 2026, beginning a Microsoft Teams phishing campaign in which attackers impersonate the target company's IT help desk and direct victims to install a fake PowerShell Cleaner MSI hosted in Microsoft Azure.
Show sources
- New SynkLoader malware pushed in Microsoft Teams phishing campaign — www.bleepingcomputer.com — 21.08.2026 21:01
-
21.08.2026 21:01 2 articles · 13d ago
SynkLoader analysis exposes a fake Windows 11 lock screen and access modules
Technical Analysis UpdateSecurity analysis of a SynkLoader sample identifies modules for host profiling, persistence, credential capture, traffic redirection, remote PowerShell execution, desktop streaming, and module status reporting after a honeypot pinged the attacker’s C2; the fake Windows 11 lock screen is a full-screen borderless GUI application that can be exposed with Alt+Tab, and the Active Directory profiling suggests likely ransomware use.
Show sources
- New SynkLoader malware pushed in Microsoft Teams phishing campaign — www.bleepingcomputer.com — 21.08.2026 21:01
- New SynkLoader malware pushed in Microsoft Teams phishing campaign — www.bleepingcomputer.com — 21.08.2026 21:01