Smartermsp iconSmartermspSep 4, 2026 ~3 min source read

SynkLoader phishing campaign uses Microsoft Teams to steal credentials via fake IT support

Researchers have identified SynkLoader, a multi-stage malware distributed through Microsoft Teams messages that impersonate IT support, display a fake Windows lock screen, and harvest credentials to enable further compromise.

Cybersecurity Threat Advisory: SynkLoader Teams phishing campaign

Share this story

Send the public story page.

Useful takeaways from this story.

SynkLoader is delivered through Microsoft Teams chats that impersonate IT support and prompt users to download and run malicious files.

The malware presents a fake Windows lock screen to capture credentials, which attackers can use for persistence, lateral movement, and secondary payload deployment.

Mitigations include restricting external Teams messaging, enforcing MFA, training users on collaboration-platform phishing, and improving endpoint detection and monitoring.

# What happened Security researchers uncovered a phishing campaign that uses Microsoft Teams messages to spread a newly discovered malware family called SynkLoader. Attackers pose as IT support, send convincing messages with a malicious file, and rely on user action to install the malware.

# How SynkLoader works SynkLoader uses a multi-stage approach:

  • Execution: When the malicious file runs, SynkLoader displays a fake Windows lock screen and prompts the user to enter credentials.
  • Credential theft: Entered credentials are captured and sent to the attacker.
  • Follow-on activity: Stolen credentials can be used to access accounts, create persistence, move laterally across networks, and install additional malware such as ransomware or data-stealing tools.

# Why this is a risk Organizations that rely on Teams for internal communication are especially exposed when federation or external messaging is allowed. Teams-based messages can look more legitimate than email, increasing the chance users will follow instructions. A successful SynkLoader infection can lead to corporate credential theft, unauthorized access to business systems, lateral movement, and deployment of secondary payloads that damage data or operations.

# Practical steps to reduce exposure The advisory lists actionable controls you can apply now:

  • Restrict external Teams communications where possible. Review and tighten federation settings so only trusted organizations can message your users.
  • Enforce multi-factor authentication (MFA) for all accounts to reduce the value of stolen credentials.
  • Implement strong password policies and periodically review privileged accounts for unnecessary access.
  • Train users to recognize social engineering tactics on collaboration platforms. Teach them to be suspicious of unsolicited IT requests, downloads, and credential prompts.
  • Deploy and maintain endpoint detection and response (EDR). Monitor endpoints for suspicious processes, credential-theft behavior, and anomalous user activity.
  • Audit Teams security settings regularly and apply Microsoft's recommended best practices for permissions and external access.
  • Encourage rapid reporting: instruct users to report suspicious messages or downloads immediately and investigate those reports quickly.

# What to watch for Monitor for these signs of compromise:

  • Unexpected Teams messages that request credential entry or prompt downloads.
  • Users reporting a sudden lock screen or credential prompt after opening an attachment or link.
  • Unusual processes or persistence mechanisms on endpoints detected by EDR tools.

# Where to find more information The advisory references additional write-ups and technical coverage for deeper investigation and context. If you have managed security services, contact your SOC for assistance in triage and containment.

# Bottom line SynkLoader leverages trust in collaboration platforms by impersonating IT staff inside Microsoft Teams. The most effective immediate defenses are reducing external Teams exposure, enforcing MFA, training users on platform-specific phishing, and strengthening endpoint monitoring so credential theft and follow-on activity can be detected and contained quickly.

More context around this story.

Warning: New Phishing Kit Targets Sales Teams
Knowbe4 iconKnowbe4Sep 25, 2026

Warning: New Phishing Kit Targets Sales Teams

Threat actors are using a new phishing kit called “GhostCode” to target sales teams with phony business inquiries, according to researchers at eSentire. The threat actors begin the attack using the targeted company’s web contact form, so the messages won’t be blocked by security filters.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app