SynkLoader malware is pushed through Microsoft Teams IT-help-desk phishing
Marcus Hutchins at Expel described a Teams campaign impersonating IT help desk and delivering a fake PowerShell Cleaner MSI hosted on Azure. The loader, first built around July 28, 2026, can drop PhishLocker, a fake lock screen that Alt+Tab reveals as a borderless app.

On August 21 BleepingComputer reported a Microsoft Teams phishing campaign documented by Marcus Hutchins at Expel. Messages impersonated IT help desk and pushed a fake PowerShell Cleaner installer hosted on Azure.
What we know
- Marcus Hutchins at Expel described Teams phishing that impersonates IT help desk and delivers a fake PowerShell Cleaner MSI hosted on Azure.
- The malware was first built around July 28, 2026, and uses Python, PowerShell, C#, and C++.
- PhishLocker presents a fake lock screen; Alt+Tab exposes it as a borderless app.
- The profiles of Active Directory size were consistent with ransomware staging.
Takeaways
- The initial access path is a Teams message that looks like internal IT support.
- PhishLocker’s fake lock screen fails a simple Alt+Tab check.
- AD sizing in the campaign fits a ransomware-staging profile.
Source: BleepingComputer


