SynkLoader
malware · malware:synkloader single-sourcesingle-source-national-cert
Previously unidentified modular loader documented by Expel on 2026-08-20, delivered by Microsoft Teams message from a company-styled onmicrosoft.com address impersonating the target's IT service desk and installed as an MSI presented as a 'PowerShell Cleaner' hosted on Azure blob storage. Six modules blending Python, PowerShell, C# and C++: a system profiler counting AD-joined computers, an in-memory DLL loader, PhishLocker (a counterfeit Windows lock screen harvesting the domain password), TrafficRedirector (a backconnect proxy defeating IP allow-listing), an interactive shell, and an outbound screen-streaming module. Expel assesses at low-to-medium confidence that it belongs to a ransomware group or an access broker selling to one (Expel, 2026-08-20).
Coverage
3
2 about it · 1 mention · first 2026-08-24 → last 2026-09-03
Latest activity
2026-09-03
The intrusion's most consequential step is a remote-management connection from a non-administrative process…
Peak priority
high
2 high
Targets
public-sector
sectors: public-sector, technology, finance · regions: europe
Sources cited
4
4 hosts
Action items (3)
Do-now tasks recorded on the entries about SynkLoader, newest first. Check the date before acting on an older one.
- Restrict inbound Microsoft Teams external collaboration to a vetted allow-list of domains, or require explicit user opt-in per external organisation, given the campaign's initial-access channel is unsolicited Teams chats/calls impersonating internal IT support.2026-09-03The intrusion's most consequential step is a…
- Restrict WinRM (TCP 5985) inbound to domain controllers and certificate authorities to a small, known set of administrative source hosts; the campaign's lateral-movement step specifically relies on WinRM being reachable from ordinary workstations to these systems.2026-09-03The intrusion's most consequential step is a…
- Restrict external and cross-tenant Microsoft Teams chat to an allow-list of federated domains, or disable it, the delivery depends on an unsolicited message from an outside tenant reaching an end user, and this is a tenant setting rather than a detection.2026-08-24SynkLoader pairs a fake Windows lock screen with a…
Defender insights
What each entry about SynkLoader tells a defender to do, newest first.
Triage
Triage
Story timeline
Every entry that names SynkLoader, newest first. Rows tagged mention only name it in passing: they are listed for completeness and add nothing to the action items, pivots or ATT&CK profile on this page.
- 2026-09-03A Teams helpdesk-impersonation campaign installs a Node.js implant (Microsoft detection name: EtherRatz) via a silent MSI, then pivots over WinRM straight to domain controllers and certificate authorities
- 2026-08-24SynkLoader: a Teams message from a lookalike tenant, an MSI called 'PowerShell Cleaner', and a six-module toolkit whose fake lock screen harvests the domain password its own tunnel then uses from the victim's IP
- 2026-08-24Switzerland's federal cyber authority reports the public sector as still the largest share of mandatory critical-infrastructure notifications, and devotes its half-year report to two things a Swiss defender can act on: the anatomy of the Polish energy sabotage, and a crypto-theft playbook that recruits its victims on LinkedIn
Hunting pivots
Affected products
ATT&CK techniques (27 across 11 tactics)
27 techniques observed across 2 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Resource DevelopmentCompromise Infrastructure: Web Services
- Initial AccessValid Accounts · Phishing: Spearphishing via Service
- ExecutionScheduled Task/Job: Scheduled Task · Command and Scripting Interpreter: PowerShell · Command and Scripting Interpreter: JavaScript · User Execution: Malicious File
- PersistenceScheduled Task/Job: Scheduled Task · Valid Accounts
- Privilege EscalationScheduled Task/Job: Scheduled Task · Valid Accounts
- StealthMasquerading · Masquerading: Match Legitimate Resource Name or Location · Valid Accounts · System Binary Proxy Execution: Msiexec · System Binary Proxy Execution: Rundll32 · Virtualization/Sandbox Evasion: System Checks · Reflective Code Loading · Social Engineering: Impersonation
- Credential AccessInput Capture: GUI Input Capture
- DiscoverySystem Service Discovery · System Network Configuration Discovery · Remote System Discovery · Process Discovery · System Information Discovery · Account Discovery: Domain Account · Virtualization/Sandbox Evasion: System Checks · Software Discovery: Security Software Discovery
- Lateral MovementRemote Services: Windows Remote Management
- CollectionInput Capture: GUI Input Capture · Screen Capture
- Command and ControlApplication Layer Protocol: Web Protocols · Proxy · Ingress Tool Transfer
Resource Development TA0042
T1584.006Compromise Infrastructure: Web Services×1
Adversaries may compromise access to third-party web services that can be used during targeting. A variety of popular websites exist for legitimate users to register for web-based services, such as GitHub, Twitter, Dropbox, Google, SendGrid, etc. Adversaries may try to take ownership of a legitimate user's access to a web service and use that web service as infrastructure in support of cyber operations. Such web services can be abused during later stages of the adversary lifecycle, such as during Command and Control (Web Service), Exfiltration Over Web Service, or Phishing. Using common services, such as those offered by Google or Twitter, makes it easier for adversaries to hide in expected noise. By utilizing a web service, particularly when access is stolen from legitimate users, adversaries can make it difficult to physically tie back operations to them. Additionally, leveraging compromised web-based email services may allow adversaries to leverage the trust associated with legitimate domains.
Evidence: 2026-08-24/synkloader-teams-helpdesk-impersonation-six-module-loader · ATT&CK page ↗
Initial Access TA0001
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-08-24/synkloader-teams-helpdesk-impersonation-six-module-loader · ATT&CK page ↗
T1566.003Phishing: Spearphishing via Service×2
Adversaries may send spearphishing messages via third-party services in an attempt to gain access to victim systems. Spearphishing via service is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of third party services rather than directly via enterprise email channels.
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · 2026-08-24/synkloader-teams-helpdesk-impersonation-six-module-loader · ATT&CK page ↗
Execution TA0002
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-08-24/synkloader-teams-helpdesk-impersonation-six-module-loader · ATT&CK page ↗
T1059.001Command and Scripting Interpreter: PowerShell×2
Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · 2026-08-24/synkloader-teams-helpdesk-impersonation-six-module-loader · ATT&CK page ↗
T1059.007Command and Scripting Interpreter: JavaScript×1
Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · ATT&CK page ↗
T1204.002User Execution: Malicious File×1
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.
Evidence: 2026-08-24/synkloader-teams-helpdesk-impersonation-six-module-loader · ATT&CK page ↗
Persistence TA0003
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-08-24/synkloader-teams-helpdesk-impersonation-six-module-loader · ATT&CK page ↗
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-08-24/synkloader-teams-helpdesk-impersonation-six-module-loader · ATT&CK page ↗
Privilege Escalation TA0004
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-08-24/synkloader-teams-helpdesk-impersonation-six-module-loader · ATT&CK page ↗
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-08-24/synkloader-teams-helpdesk-impersonation-six-module-loader · ATT&CK page ↗
Stealth TA0005
T1036Masquerading×1
Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names.
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · ATT&CK page ↗
T1036.005Masquerading: Match Legitimate Resource Name or Location×1
Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.
Evidence: 2026-08-24/synkloader-teams-helpdesk-impersonation-six-module-loader · ATT&CK page ↗
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-08-24/synkloader-teams-helpdesk-impersonation-six-module-loader · ATT&CK page ↗
T1218.007System Binary Proxy Execution: Msiexec×1
Adversaries may abuse msiexec.exe to proxy execution of malicious payloads. Msiexec.exe is the command-line utility for the Windows Installer and is thus commonly associated with executing installation packages (.msi). The Msiexec.exe binary may also be digitally signed by Microsoft.
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · ATT&CK page ↗
T1218.011System Binary Proxy Execution: Rundll32×1
Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. Shared Modules), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations. Rundll32.exe is commonly associated with executing DLL payloads (ex: <code>rundll32.exe {DLLname, DLLfunction}</code>).
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · ATT&CK page ↗
T1497.001Virtualization/Sandbox Evasion: System Checks×1
Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · ATT&CK page ↗
T1620Reflective Code Loading×1
Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads. Reflective loading involves allocating then executing payloads directly within the memory of the process, vice creating a thread or process backed by a file path on disk (e.g., Shared Modules).
Evidence: 2026-08-24/synkloader-teams-helpdesk-impersonation-six-module-loader · ATT&CK page ↗
T1684.001Social Engineering: Impersonation×1
Adversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf. For example, adversaries may communicate with victims (via Phishing for Information, Phishing, or Internal Spearphishing) while impersonating a known sender such as an executive, colleague, or third-party vendor. Established trust can then be leveraged to accomplish an adversary’s ultimate goals, possibly against multiple victims.
Evidence: 2026-08-24/synkloader-teams-helpdesk-impersonation-six-module-loader · ATT&CK page ↗
Credential Access TA0006
T1056.002Input Capture: GUI Input Capture×1
Adversaries may mimic common operating system GUI components to prompt users for credentials with a seemingly legitimate prompt. When programs are executed that need additional privileges than are present in the current user context, it is common for the operating system to prompt the user for proper credentials to authorize the elevated privileges for the task (ex: Bypass User Account Control).
Evidence: 2026-08-24/synkloader-teams-helpdesk-impersonation-six-module-loader · ATT&CK page ↗
Discovery TA0007
T1007System Service Discovery×1
Adversaries may try to gather information about registered local system services. Adversaries may obtain information about services using tools as well as OS utility commands such as <code>sc query</code>, <code>tasklist /svc</code>, <code>systemctl --type=service</code>, and <code>net start</code>. Adversaries may also gather information about schedule tasks via commands such as `schtasks` on Windows or `crontab -l` on Linux and macOS.
Evidence: 2026-08-24/synkloader-teams-helpdesk-impersonation-six-module-loader · ATT&CK page ↗
T1016System Network Configuration Discovery×1
Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems. Several operating system administration utilities exist that can be used to gather this information. Examples include Arp, ipconfig/ifconfig, nbtstat, and route.
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · ATT&CK page ↗
T1018Remote System Discovery×2
Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system. Functionality could exist within remote access tools to enable this, but utilities available on the operating system could also be used such as Ping, <code>net view</code> using Net, or, on ESXi servers, `esxcli network diag ping`.
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · 2026-08-24/synkloader-teams-helpdesk-impersonation-six-module-loader · ATT&CK page ↗
T1057Process Discovery×1
Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Administrator or otherwise elevated access may provide better process details. Adversaries may use the information from Process Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Evidence: 2026-08-24/synkloader-teams-helpdesk-impersonation-six-module-loader · ATT&CK page ↗
T1082System Information Discovery×2
An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes.
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · 2026-08-24/synkloader-teams-helpdesk-impersonation-six-module-loader · ATT&CK page ↗
T1087.002Account Discovery: Domain Account×1
Adversaries may attempt to get a listing of domain accounts. This information can help adversaries determine which domain accounts exist to aid in follow-on behavior such as targeting specific accounts which possess particular privileges.
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · ATT&CK page ↗
T1497.001Virtualization/Sandbox Evasion: System Checks×1
Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · ATT&CK page ↗
T1518.001Software Discovery: Security Software Discovery×1
Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment. This may include things such as cloud monitoring agents and anti-virus. Adversaries may use the information from Security Software Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · ATT&CK page ↗
Lateral Movement TA0008
T1021.006Remote Services: Windows Remote Management×1
Adversaries may use Valid Accounts to interact with remote systems using Windows Remote Management (WinRM). The adversary may then perform actions as the logged-on user.
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · ATT&CK page ↗
Collection TA0009
T1056.002Input Capture: GUI Input Capture×1
Adversaries may mimic common operating system GUI components to prompt users for credentials with a seemingly legitimate prompt. When programs are executed that need additional privileges than are present in the current user context, it is common for the operating system to prompt the user for proper credentials to authorize the elevated privileges for the task (ex: Bypass User Account Control).
Evidence: 2026-08-24/synkloader-teams-helpdesk-impersonation-six-module-loader · ATT&CK page ↗
T1113Screen Capture×2
Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as <code>CopyFromScreen</code>, <code>xwd</code>, or <code>screencapture</code>.
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · 2026-08-24/synkloader-teams-helpdesk-impersonation-six-module-loader · ATT&CK page ↗
Command and Control TA0011
T1071.001Application Layer Protocol: Web Protocols×1
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · ATT&CK page ↗
T1090Proxy×1
Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, reduce the number of simultaneous outbound network connections, provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between victims to avoid suspicion. Adversaries may chain together multiple proxies to further disguise the source of malicious traffic.
Evidence: 2026-08-24/synkloader-teams-helpdesk-impersonation-six-module-loader · ATT&CK page ↗
T1105Ingress Tool Transfer×1
Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · ATT&CK page ↗
Entries about SynkLoader (2)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- bacs.admin.ch1 (25%)
- cms.news.admin.ch1 (25%)
- expel.com1 (25%)
- microsoft.com1 (25%)
All cited sources (4)
- bacs.admin.chBundesamt für Cybersicherheit (BACS), press releasehttps://www.bacs.admin.ch/de/newnsb/vzO9wG1V7K0D-m73EJw8W
- cms.news.admin.chBundesamt für Cybersicherheit (BACS), Halbjahresbericht 2026/Ihttps://cms.news.admin.ch/fileservice/sdweb-docs-prod-nsbcch-files/files/2026/08/24/25a75eab-7e61-467e-aeeb-47a7329ad921.pdf
- expel.comthis pipeline covers today from Expel's SynkLoader casehttps://expel.com/blog/synkloader-when-you-throw-in-everything-but-the-kitchen-sink/
- microsoft.comMicrosoft Threat Intelligencehttps://www.microsoft.com/en-us/security/blog/2026/09/02/impersonating-it-support-threat-actors-turn-remote-session-into-enterprise-wide-access/