Skip to main content

Command Palette

Search for a command to run...

SynkLoader: Malware mới phát tán qua Teams phishing bằng fake lock screen

Updated
11 min readView as Markdown
SynkLoader: Malware mới phát tán qua Teams phishing bằng fake lock screen

Tóm tắt chiến dịch

Ngày 18/08/2026, các chuyên gia bảo mật phát hiện malware family hoàn toàn mới khi điều tra cảnh báo EDR bất thường trên mạng khách hàng. Malware này, được đặt tên SynkLoader, lây nhiễm qua Microsoft Teams. Kẻ tấn công giả làm IT helpdesk, dụ nhân viên cài file MSI độc hại host trên Azure Blob Storage.

Điểm khác biệt lớn nhất: SynkLoader có module PhishLocker tạo màn hình khóa Windows 11 giả để lấy password thật của user. Password này kết hợp với reverse proxy, attacker đăng nhập hệ thống nội bộ trực tiếp từ máy nạn nhân, bypass IP allowlist sạch sẽ.

Các trung tâm giám sát hiện tại build detection stack cho credential theft xoay quanh Mimikatz, LSASS dump, DCSync, Kerberoasting. Toàn bộ đều là kỹ thuật tầng hệ thống, artifact rõ ràng. PhishLocker đi khác hoàn toàn: social engineering ngay trên máy local, không tạo artifact credential access nào mà EDR thường bắt.

Combo PhishLocker + TrafficRedirector tạo ra kịch bản mà SIEM truyền thống gần như mù: login đến từ IP nội bộ hợp lệ, credential đúng, không brute force, không password spray. Trong môi trường SSO, một password mở tất cả. Đây không phải lý thuyết, đây là chính xác những gì SynkLoader được thiết kế để làm.

Xu hướng malware multi-language ngày càng rõ ở các loader mới. SynkLoader đẩy lên extreme: Python -> C# -> C++ -> PowerShell trong cùng execution chain. EDR rule thường viết cho từng runtime riêng (Python AMSI, .NET ETW, PowerShell ScriptBlock logging) nhưng chưa có nhiều rule correlate cross-runtime behavior.

Teams đang được doanh nghiệp VN dùng rộng rãi. Nhiều tổ chức cấu hình Teams cho phép nhận tin nhắn external mà không cảnh báo rõ ràng cho user.

Theo quan sát của đội ngũ bảo mật FPT Threat Intelligence,các nhân viên trong nước trust tin nhắn Teams cao hơn email (email phishing đã được training nhiều năm), trong khi nhận thức về Teams phishing gần như chưa có. SynkLoader minh họa chính xác lỗ hổng này.


Chuỗi kỹ thuật tấn công

Phase 1 - Teams phishing giả IT helpdesk

Kẻ tấn công dùng tài khoản dạng <username>@<company>.onmicrosoft.com liên hệ mục tiêu trên Teams với tên hiển thị "IT Service Desk". Domain onmicrosoft.com là domain mặc định Microsoft 365, nên tin nhắn trông đáng tin hơn email phishing thông thường rất nhiều.

Microsoft đã cảnh báo từ đầu 2026 rằng vector này ngày càng phổ biến. Và SynkLoader khai thác đúng điều đó.

Nạn nhân được dẫn tải file MSI từ Azure Blob Storage:

https://filereserve.blob.core.windows[.]net/vgnghuyk/331/331.msi

File MSI hiển thị tên "PowershellCleaner", giả làm công cụ dọn dẹp hệ thống.

Phase 2 - Chuỗi thực thi in-memory

MSI chạy xong sẽ extract ra %LocalAppData%\PowershellCleaner\script\ hai file: cleaner.ps1 (PowerShell script mồi) và archive6.zip (chứa Python framework cùng toàn bộ malware).

cleaner.ps1 mở PowerShell ẩn, build string từ giá trị hex bằng kỹ thuật -join [char[]], rồi chạy qua iex. Từ đây trở đi không có gì ghi ra disk nữa. Chuỗi giải mã 3 lớp:

  1. Hex decode ra command

  2. AES-CBC decrypt payload từ chuỗi Base64

  3. Thực thi qua [System.Management.Automation.ScriptBlock]::Create()

Script cuối rất đơn giản: tạo thư mục 16 ký tự random dưới %AppData%, extract archive6.zip vào, chạy Python loader.

Phase 3 - Python loader tự cung tự cấp

Thư mục extract chứa Python runtime đầy đủ (Windows không có sẵn Python), cùng:

  • ss.py - loader chính, obfuscated nặng

  • msvcp150.dll - không phải Visual C++ runtime, mà là C# DLL chạy PowerShell in-memory

  • msvcp160.dll - cũng không phải runtime, mà là C++ DLL loader native

  • Các thư viện Python precompiled

Loader chọn random 1 trong 3 C2 domain hardcoded, build URL theo format https://<domain>/<token_1>/<victim_id>/<token_2>, rồi bắt đầu beacon. Chuỗi 16 ký tự random đã tạo trước đó chính là victim ID xuyên suốt infection chain.

Phase 4 - C2 bằng ChaCha20 sửa đổi

Giao tiếp C2 dùng ChaCha20 nhưng Sigma constant đã bị đổi:

# Sigma mặc định
SIGMA_128 = "expand 16-byte k"
SIGMA_256 = "expand 32-byte k"

# Sigma của SynkLoader
SIGMA_128 = b"mlswgtppayebtezk"
SIGMA_256 = b"lwifnrfiosmfrubf"

Victim ID làm luôn encryption key. Beacon gửi mỗi 90-120 giây (random interval), payload JSON encrypted:

{
  "ping": {
    "local_id": "<VICTIM_ID>",
    "timestamp": "<ISO_TIMESTAMP>",
    "ping": true
  }
}

C2 trả về Python code chạy thẳng qua exec(). Attacker muốn chạy gì trên máy nạn nhân đều được.

Phase 5 - Module deployment tùy target

Tùy vào thông tin thu thập từ môi trường nạn nhân, attacker chọn module nào sẽ gửi xuống. Expel đã reverse C2 protocol và dựng honeypot giả làm mạng AD vài nghìn máy để kéo attacker deploy toàn bộ toolkit. Cách này cho phép Expel thu thập được gần như tất cả module có trong bộ SynkLoader.


Phân tích kỹ thuật: Các module SynkLoader

System Profiler

Module đầu tiên C2 gửi xuống. Về mặt kiến trúc, nó gọi msvcp150.dll (C# DLL) qua CPython để chạy PowerShell in-memory. Chuỗi thực thi là Python -> C# DLL -> PowerShell, 3 ngôn ngữ cho 1 module.

DLL export hai function RunPowerShellRunPowerShellW. Trước khi Expel publish, không có reference công khai nào về hai function này. Compile timestamp: 08:02:11 AM, 28/07/2026.

Dữ liệu thu thập:

hostname, username, runas (SYSTEM/ADMIN/USER)
processes, services
domain, AD_counter
systeminfo, whoami /all

AD_counter là trường đáng để ý. Đây là metric kinh điển của ransomware actor: mạng càng lớn, encrypt càng nhiều host, tiền chuộc càng cao. Thấy field này trong profiler gần như chắc chắn mục đích cuối là ransomware hoặc bán access.

Developer để lộ PDB path:

C:\Users\genry\source\repos\pwshnewdll\x64\Release\pwshnewdll.pdb

Username genry. Ghi nhớ cái này.

Persistence qua COM interface

Module persistence chạy nhiều lớp: Python gọi msvcp160.dll (C++ native) để map DLL payload vào memory, DLL đó export function nm() tạo scheduled task qua COM interface CLSID_TaskScheduler.

Điểm hay ở đây: thay vì gọi schtasks.exe mà EDR nào cũng monitor, malware nói chuyện thẳng với Task Scheduler service qua RPC/ALPC. Rất nhiều EDR rule chỉ bắt command line liên quan scheduled task, kỹ thuật COM này đi qua sạch.

Task có 2 trigger: khi user logon (persistence qua reboot) và hàng ngày 10:00 AM (chưa rõ mục đích). Tên task là 12 ký tự random, thay đổi mỗi lần chạy. Action khởi chạy ss.py qua pythonw.exe mà malware ship theo.

PDB path lại lộ cùng developer:

C:\Users\genry\source\repos\schdtaks_atlg_dll\x64\Release\schdtaks_atlg_dll.pdb

Chú ý typo "schdtaks" thay vì "schtasks". Dev viết nhầm tên repo.

PhishLocker: Fake lock screen lấy password

Đây là module hay nhất trong bộ toolkit. Theo Expel, đây là lần đầu tiên kỹ thuật fake lock screen xuất hiện dưới dạng malware local (trước đó chỉ có biến thể browser-based đã bị loại bỏ hơn chục năm trước).

Cách nó chạy: load DLL khoảng 500 KB in-memory, lấy username qua GetUserName(), lấy hình nền lock screen từ C:\Windows\Web\Screen\, render cửa sổ full-screen borderless giống y Windows 11 lock screen. User nhập password, gửi về C2.

Tại sao nó nguy hiểm hơn Mimikatz? Vì nó lấy raw password, không phải hash. Mimikatz hay LSASS dump cho NTLM hash, còn cần crack hoặc pass-the-hash. PhishLocker cho password thật, trong môi trường SSO (Single Sign-On) một password mở được email, file share, VPN, cloud console, tất cả.

Và EDR gần như không có rule nào detect fake lock screen. Không trigger LSASS alert, không inject process nào đáng ngờ, không gọi API credential theft thông thường.

Nhưng PhishLocker có vài điểm yếu mà user tinh ý nhận ra được:

  • Alt+Tab vẫn hoạt động (lock screen thật block Alt+Tab)

  • Ctrl+Alt+Delete vẫn hoạt động

  • Thiếu blur background khi focus password prompt (Windows 11 thật có)

  • Không verify password qua Windows Authentication, nhập bất kỳ gì cũng qua

  • Code viết cho Windows 11, chạy trên Windows 10 sẽ trông khác

TrafficRedirector: Reverse proxy backconnect

TrafficRedirector là backconnect proxy tự build, protocol kiểu HTTP CONNECT. Khác proxy thường (listen kết nối đến), module này connect ra ngoài tới server attacker rồi chờ lệnh.

Hai công dụng: bypass IP allowlist (attacker truy cập dịch vụ internet qua IP máy nạn nhân, hệ thống allowlist coi là truy cập hợp lệ) và truy cập service nội bộ chỉ accessible qua LAN.

Kết hợp với password từ PhishLocker: attacker có username + password + tunnel qua máy nội bộ = đăng nhập mọi hệ thống SSO mà không trigger alert IP lạ hay geolocation bất thường. Combo này gần như invisible với SIEM truyền thống.

Module dùng C2 domain riêng dondermicapp[.]net, tách biệt khỏi loader.

Interactive Shell (RAT)

Reverse shell polling C2 endpoint riêng nhận command real-time. Command chạy qua msvcp150.dll (RunPowerShell in-memory). Output trả qua Python deque() rồi gửi lên C2.

Module có 2 endpoint: một nhận command, một upload response. Pattern kiểu này cho thấy thiết kế hướng hands-on-keyboard attack.

StreamMaster (VNC)

VNC module viết bằng Python, kết nối outbound (không listen port inbound). Lưu ý: đây không phải HVNC (Hidden VNC). Module stream thẳng session hiện tại của user, nạn nhân sẽ thấy chuột và bàn phím di chuyển.

Expel ghi nhận dấu hiệu "vibe-coded" ở module này: comment rất formal, verbose, spelling hoàn hảo, grammar chuẩn, không match với open-source project nào. Pattern này giống code do AI sinh ra, nơi comment chi tiết quá mức so với thói quen viết code thực tế.

Module Status Script

Script nhỏ, gửi xuống sau khi attacker phát hiện một số module không chạy trên honeypot của Expel. Kiểm tra trạng thái alive/dead của các thread rồi báo lại C2. Từ đây attacker nhận ra honeypot và ngắt kết nối.

IOC và Artifacts

# File Hashes (SHA-256) - Nguồn: Expel, 20/08/2026

# Initial Installer
331.msi                    151d2a7f52f047638ca8ad80c859c6bfe04d7510fb10933817fa0e3ba5d07a11
cleaner.ps1                80f08360ba768b152b71abb1cab557f552a13de18c83fe8e6396a197feec9185
archive6.zip               209F69A6CA859F05C954096B30391A43FDA33C9ED264DFDCCF806697F04B06A8

# Main Loader và DLLs
ss.py                      D150C70D2732DF17AA77991B9EBF4C896F044445E900978581D9598DFA5DC98C
msvcp150.dll (C# PS exec)  61F961CFEBDF9967844526649B4B75BBA5B1B83210B70AA1BFFE3F64E6AC3112
msvcp160.dll (DLL loader)  8207D8D949530EA063FFD5D47EE81B74BF718EC0A4755E2349E6AF9B91E92DC1

# Module Loaders
Profiling module loader    C4ACDA412774C292F0DB5D64467A2DD09282CDEA43C41967E8BF90F6298ACCF3
Persistence module loader  63622C1DDB3E2A9F11CAC192E13AC7494F558516B19D5D8F140F6D0D4D38EA84
Fake lock screen loader    A335E75B78B601EBC5C258975D95FD79AA21F836FC6B79D82E9A22C596133F07

# Module DLLs (in-memory)
Persistence DLL            0428FBDEFA8DDA10CE8FC12B1B516641E83CD5088388168E3F1A0BE1432B4077
Fake lock screen DLL       CB1C657F74B9E57F5E81126179128E8DB949D1D4196BE9DCB890341E222FD384
# Network Indicators

# Loader C2 Domains
neversoftmain[.]net
rootfarmapp[.]net
tripinupdate[.]net

# Module-specific C2 Domains
dondermicapp[.]net          (TrafficRedirector)
aroclenetapp[.]net          (VNC StreamMaster)

# Initial Installer URL
https://filereserve.blob.core.windows[.]net/vgnghuyk/331/331.msi
# Host-based Indicators

# File Paths
%LocalAppData%\PowershellCleaner\script\cleaner.ps1
%LocalAppData%\PowershellCleaner\script\archive6.zip
%AppData%\<random 16 chars>\fl\ang\ss.py
%AppData%\<random 16 chars>\fl\ang\pythonw.exe
%AppData%\<random 16 chars>\fl\ang\msvcp150.dll
%AppData%\<random 16 chars>\fl\ang\msvcp160.dll

# Scheduled Task
Tên: 12 ký tự alphanumeric random (đổi mỗi lần)
Action: pythonw.exe chạy ss.py
Trigger: User Logon + Daily 10:00 AM

# PDB Paths (Developer artifacts)
C:\Users\genry\source\repos\pwshnewdll\x64\Release\pwshnewdll.pdb
C:\Users\genry\source\repos\schdtaks_atlg_dll\x64\Release\schdtaks_atlg_dll.pdb

Lưu ý cho defenders: Hash các module là unique per infection. Mỗi victim nhận bộ module hash khác nhau, nên hash-based detection giá trị hạn chế. Ưu tiên behavioral: pythonw.exe chạy từ AppData, DLL load bất thường, scheduled task creation qua COM.


Khuyến nghị

Kiểm tra policy Microsoft Teams: restrict tin nhắn từ external tenant, hoặc ít nhất bật cảnh báo rõ ràng khi user nhận tin nhắn ngoài tổ chức. Block hoặc restrict MSI execution từ %LocalAppData%%AppData% qua AppLocker/WDAC. Hunt trên endpoint: tìm pythonw.exe chạy từ path dưới %AppData% với argument trỏ tới .py. Scan IOC network (5 domain + URL ở trên) trên proxy/firewall log.

Review scheduled task toàn bộ endpoint, tìm task tên random có action chạy pythonw.exe. Monitor PowerShell execution từ parent process pythonw.exe, đây là anomaly rõ. Kiểm tra DLL load: msvcp150.dll hoặc msvcp160.dll load từ user profile path thay vì System32. Tăng cường detection cho scheduled task creation qua COM (Event ID 4698 vẫn ghi nhận, nhưng cần parse trigger/action thay vì dựa parent process).

Triển khai training về Teams phishing, bổ sung scenario IT helpdesk impersonation vào phishing simulation. Evaluate application whitelisting cho endpoint, restrict Python và MSI từ non-standard paths. Review detection coverage cho cross-runtime chain: Python -> .NET -> native -> PowerShell. Deploy network detection cho outbound tunnel/reverse proxy từ server và workstation segment. Hướng dẫn user: gặp lock screen bất ngờ thì thử Alt+Tab, nếu hoạt động thì đó không phải lock screen thật.


Tài liệu tham khảo

  1. Expel, "SynkLoader: when you throw in everything but the kitchen sink" (20/08/2026): https://expel.com/blog/synkloader-when-you-throw-in-everything-but-the-kitchen-sink/

  2. BleepingComputer, "New SynkLoader malware pushed in Microsoft Teams phishing campaign" (21/08/2026): https://www.bleepingcomputer.com/news/security/new-synkloader-malware-pushed-in-microsoft-teams-phishing-campaign/

  3. Dark Reading, "Tricky 'SynkLoader' Multitool May Herald Ransomware" (24/08/2026): https://www.darkreading.com/threat-intelligence/tricky-synkloader-multitool-ransomware

  4. The Hacker News, "WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords" (08/2026): https://thehackernews.com/2026/08/wordlistloader-delivers-amatera-via.html

  5. Cyber Security News, "Microsoft Teams Phishing Deploys New SynkLoader Malware" (08/2026): https://cybersecuritynews.com/microsoft-teams-phishing/

More from this blog

F

FPT IS Security

972 posts

Dedicated to providing insightful articles on cybersecurity threat intelligence, aimed at empowering individuals and organizations to navigate the digital landscape safely.