type: incident ยท created: 2026-08-23 ยท updated: 2026-08-23 ยท tags: [incident, malware, credential-theft, phishing, teams, social-engineering] ยท confidence: high ยท severity: high ยท affected_sectors: [technology, finance, government] ยท au_impact: false
Expel researchers, including Marcus Hutchins, detailed a previously unknown malware family dubbed SynkLoader distributed through Microsoft Teams phishing campaigns in which attackers impersonate the target company's IT help desk and direct victims to install a fake "PowerShell Cleaner" tool. SynkLoader steals credentials via a fake lock screen, continuing the help-desk-impersonation tradecraft Microsoft flagged earlier this year as increasingly common.
Source
- BleepingComputer โ Tier 2/4, verified, 2026-08-21