tech 🚨 Teams phishing pushes SynkLoader to steal Windows passwords
Microsoft Teams phishing is tricking users into installing SynkLoader malware via fake IT helpdesk requests. This campaign, identified by Expel, first appeared around July 28, 2026, using an MSI file from Azure Blob Storage. The malware gathers system data and deploys PhishLocker to capture raw Windows passwords. Attackers can then use this info to move across internal services undetected. Employees must verify support messages through official internal channels to stay safe.