New 'SynkLoader' Malware Could Be the Opening Move in Future Ransomware Attacks

Researchers at Expel found a modular malicious program that tricks employees into handing over their passwords, hides from security tools, and looks built to prepare corporate networks for ransomware.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 5 min read
A corporate employee at a desk receiving a phishing message, overlaid with technical analysis showing malware code structure and ransomware preparation modules
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Expel researchers discovered SynkLoader on a client's network on 18 August, with code evidence suggesting it was first deployed on 28 July.
  • The attack began with a phishing email sent from a genuine Microsoft 365 account, dressed up to look like a message from the victim's own IT Service Desk.
  • SynkLoader includes a fake Windows lock screen that captures employees' passwords when they type them in.
  • Researchers believe the tool was likely built by a ransomware group or a criminal broker who sells network access to ransomware gangs.
  • No attribution to a named group has been confirmed; the creators' identity remains unknown at medium-to-low confidence.

A newly discovered malicious program called SynkLoader is raising concerns among security researchers because of how carefully it was built to slip past corporate defences. Our first look at it on 21 August focused on the Microsoft Teams delivery vector; this report covers the fuller picture Expel has since shared. Marcus Hutchins and his colleagues at Expel coined the name from "everything but the kitchen sink," a nod to how many tricks the program throws at its targets.

How did the attack start?

The criminals didn't use cheap, obvious tricks. They registered a genuine Microsoft 365 account and sent a phishing email, a fake message designed to deceive the recipient, that identified itself as the victim's IT Service Desk. The malicious installer was hosted on an official Microsoft Azure storage page, lending it a surface legitimacy.

The email asked the employee to install what it called a PowerShell system maintenance tool. PowerShell is a built-in Windows program that runs commands on a computer. The "tool" was anything but maintenance software.

What does SynkLoader actually do?

Once installed, the program deploys several components working together. Instructions run entirely in temporary memory rather than being written to the hard drive, which makes the malware harder for security software to spot.

It also drops a stripped-down Python programming environment into a random folder. Python isn't commonly used in malware, which helps the program avoid triggering security alerts. Hutchins notes that a Python installation sitting in an unusual folder location is itself a red flag worth watching for.

A collection of supporting files called DLLs (dynamic link libraries, small programs Windows apps call on to do specific jobs) extends what Python can't do on its own. One DLL profiles the victim's entire network: how many computers belong to it, what services are running, and what access level the local user holds.

"To measure the size of the victim's network is typically something only of interest to ransom groups," Hutchins told Dark Reading. Espionage-focused state-sponsored groups generally already know their target's scale. Opportunistic ransomware gangs need to size up a network before they can price a ransom demand.

Other modules give criminals live access to the victim's screen and keyboard, create a recurring background task to keep the infection alive between restarts, and route the attackers' internet traffic through the victim's own connection.

The fake lock screen stealing passwords

The most striking component is what researchers called "PhishLocker." It presents the victim with what looks exactly like a standard Windows login screen, blocking use of the computer until they type their password. That password goes straight to the attackers.

This matters more now than it once did. Many companies use single sign-on systems, meaning the same password that unlocks a laptop also unlocks email and financial tools. One captured password can open a wide corridor through a company's internal world.

Component What it does
PowerShell script Runs instructions in temporary memory to avoid detection
Python environment Hosts the malware's core in an unusual location
System profiler DLL Maps the victim network's size and user privileges
Persistence module Creates a hidden recurring task to survive reboots
Remote access module Streams the victim's screen; enables keyboard and mouse control
PhishLocker DLL Shows a fake Windows lock screen to steal the user's password

Should employees be worried?

If you receive an unexpected email from your "IT department" asking you to install a tool, pause before clicking. Legitimate IT teams rarely ask employees to install software by following a link in an email. When in doubt, call your IT desk directly using a number you already have.

No confirmed ransomware attacks have been linked to SynkLoader yet. The program appears to be in early deployment, and its creators haven't been publicly identified. Expel hasn't publicly overlapped its infrastructure with any currently tracked APT cluster (an advanced persistent threat, a hacking group running long-term, targeted campaigns) or known ransomware affiliate. Attribution remains open.

What strikes me most here is how little attribution pressure there is on this one. The profiler DLL is the clearest signal pointing toward ransomware or an initial access broker, but it's a single data point. Watch whether any ransomware intrusions in the coming weeks show matching infrastructure or delivery patterns.

Common questions

Am I at personal risk from SynkLoader?

For now, this malware appears aimed at corporate networks rather than home users. The most practical thing anyone can do at work is treat unexpected emails asking for software installs with scepticism, even if the sender looks familiar.

How would a company know if it was infected?

Hutchins points to one concrete signal: a Python installation sitting in an unexpected folder inside the Windows AppData directory. Security teams can search for out-of-place Python executables as a starting point.

© 2026 Threat Vectr