Skip to content
Back to Guavy Wire
Stocks

SynkLoader Malware Targets Microsoft Teams Users with Fake Lock Screen

Instruments
MSFT
Share

A new malware family called SynkLoader has been discovered in Microsoft Teams phishing campaigns. The attackers impersonate the target company's IT help desk, a tactic highlighted by Microsoft earlier this year as increasingly common in multi-stage attacks.

Expel's security researcher Marcus Hutchins explained that the attacks direct the victim to install a fake 'PowerShell Cleaner' executable (.MSI) hosted in Microsoft Azure. The download appears trustworthy due to its hosting on Azure.

The analysis of the malware showed compile dates and file timestamps indicating it was first compiled and distributed around July 28, 2026.

More on Stocks

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc