SynkLoader Malware Exploits Microsoft Teams for Corporate Network Infiltration
A new malware family called SynkLoader has been spreading through Microsoft Teams phishing campaigns. Attackers impersonate corporate IT help desks and direct victims to install a fake PowerShell Cleaner package hosted on Microsoft Azure.
The malware combines multiple tools for remote access and persistence, including Python, PowerShell, C#, and C++. It can steal Windows credentials through a convincing fake lock screen and deploy additional modules based on the infected organisation’s environment.
Researchers found that SynkLoader was first compiled and distributed around July 28, 2026. The installer extracts a PowerShell script named cleaner.ps1 along with a ZIP archive containing a Python framework, a malicious Python script, precompiled Python libraries, and fake Microsoft runtime DLLs.