-
SynkLoader malware is being distributed through phishing campaigns that impersonate Microsoft Teams to trick victims into executing malicious payloads.
-
Threat actors are abusing FTP server banners to deliver a newly identified Windows malware strain to targeted systems.
-
Nimbus Manticore actors appear to be expanding their operational infrastructure across Europe, the Middle East, and Asia.
1. New SynkLoader malware using Teams phishing and screenlocking to steal credentials
Summary
SynkLoader is a sophisticated malware family distributed via Microsoft Teams phishing campaigns. It uses a multi-language, modular architecture to steal credentials and establish persistent remote access, primarily through a deceptive fake Windows lock screen. Its design suggests potential use in ransomware operations.
Category: Threat Actor Activities
Industry: Multiple
Sources
-
https://expel.com/blog/synkloader-when-you-throw-in-everything-but-the-kitchen-sink/
-
https://www.ontinue.com/resource/python-implant-hiding-its-entire-c2-inside-microsoft-365-azure/
-
Internal OSec Research
Analyst comments
SynkLoader is spread through Microsoft Teams phishing campaigns in which the actor impersonates a company IT help desk to deploy a fake “PowerShell Cleaner” executable. The executable steals credentials via a deceptive lock screen. The malware was first compiled around July 28, 2026. It combines Python, PowerShell, C#, and C++ across its modules and is installed through an .MSI file hosted on Microsoft Azure.
Its modules include a System Profiler, Persistence Module, PhishLocker, TrafficRedirector, Interactive Shell (RAT), StreamMaster (VNC), and Module Status Script. Each is designed to gather system information, maintain access, and control the infected host. The threat actor is suspected to be an Initial Access Broker (IAB) operating in support of ransomware campaigns.
SynkLoader shares several characteristics with the recently identified malware TWINLOOT: both use a fake lock screen for credential theft, Python loaders, and leverage Microsoft Azure tenants for phishing and initial victim contact. Both actors are believed to be operating as Initial Access Brokers (IAB), with TWINLOOT suspected of ties to CHAOS ransomware, though no official attribution currently exists. SynkLoader does not use STUN/TURN server relays or the mandatory user-profile persistence mechanisms observed in TWINLOOT. The shared use of screen-locking and legitimate Microsoft infrastructure represents an emerging tactic of an old technique.
During the attack chain, the malware executes several PowerShell commands from the .MSI, drops a self-contained Python script, and installs second-stage files to disk. For persistence, it loads DLLs to create scheduled tasks: one that runs at user logon and one that runs at 10:00 AM daily. These tasks are named as seemingly random alphanumeric strings. The malware drops most of its files into %APPDATA%\fl\ang\. If compromise is suspected, this directory should be the first location examined for forensic artifacts.
A notable technique is the fake lock screen, which closely mimics the default Windows 11 lock screen. Pressing Alt+Tab is a clear indicator that the lock screen is fake, as it reveals other open applications behind it. On workstations with a custom lock screen set by the user, the appearance of the default Windows 11 background image is also a tell. The fake lock screen can be dismissed by entering any string that is not the user’s actual password.
Actionable guidance
Users should independently verify IT requests and avoid installing unsolicited MSI files. Pressing Ctrl+Alt+Delete or Alt+Tab can confirm whether a lock screen is genuine. Users with a custom lock screen configured should treat the appearance of a default Windows 11 background as a suspicious indicator.
As with TWINLOOT, it may become necessary to allowlist known company Azure domains and block access from unknown ones. Installing software and executing PowerShell should be restricted to IT staff to limit potential impact. Based on currently active domains, the actor favors .net domains hosted on ASN 399629.
2. Hackers use novel FTP dead-drop resolver technique
Summary
Threat actors are leveraging FTP banners to conceal commands that deliver two new remote access trojans, E4del and PINHOLE, using an unusual dead-drop resolver technique observed since July 2026.
Category: Threat Actor Activities
Industry: Multiple (Likely within Spanish speaking regions such as Mexico and LATAM)
Sources
-
https://socradar.io/blog/ftp-banners-new-dead-drop-resolver-rats/
-
Internal OSec Research
Analyst comments
Threat actors are embedding commands for two undocumented RATs, E4del and PINHOLE, inside FTP server banner messages, the initial greeting sent to a connecting system. The attack begins with a ZIP archive that triggers an LNK-based infection chain, likely delivered via phishing. E4del is disguised as Discord and supports command execution, payload download, and related actions. PINHOLE retrieves its C2 configuration from unconventional sources including Pinterest pins. It uses techniques designed for a minimal host footprint. Researchers identified this technique in July 2026. While versatile, it is assessed as less stealthy than traditional web-based dead-drop resolvers due to the potential visibility of FTP connections to unknown servers.
These two clusters are assessed as closely aligned. Both target Spanish-speaking victims, with infrastructure and domain references pointing to Mexican targets specifically. The campaign is ongoing: the threat actor’s infrastructure and statistics panels show a significant increase in connections since initial reporting. Both malware families are stealers designed primarily for credential theft using Spanish-language lures. Samples of the .LNK or .ZIP initial-stage files were not recovered. Both stealers may likely be sold or offered, or will soon be available, as Malware-as-a-Service offerings based on activity, however this has not been fully verified at this time. Activity was confirmed against FTP attacker infrastructure and live connection to the malware panels on August 25th.
Persistence artifacts differ between clusters. E4del uses a Run key at HKCU\Software\Microsoft\Windows\CurrentVersion\Run pointing to a Discord.exe binary in the current user’s %APPDATA% folder. PINHOLE uses a Load value at HKCU\Software\Microsoft\Windows\CurrentVersion\ pointing to a payload at C:\Users\{user}\AppData\Local\Packages\{random-string}\{random-string}.exe. Both registry locations should be examined if compromise is suspected.
PINHOLE’s C2 activity includes callbacks to Pinterest and SurveyMonkey. Wide use of these channels was not observed in current data. The Pinterest account fallbackmexapanel was identified with only two entries.
The novel technique shared by both families is the delivery of PowerShell execution strings via FTP server banners. The commands gathered from known active infrastructure are listed below.
The most interesting and novel aspect of both of these malware families is the use of command and PowerShell strings being served to download and perform other functions of the malware.
Actionable guidance
Blocking or restricting PowerShell execution for users outside IT-related roles is recommended to limit execution of the downloader used by both malware variants. Because these commands are retrieved over FTP banners, identifying traffic on port 21 containing strings such as PowerShell.exe, conhost.exe, bitsadmin, or New-Object System.Net.WebClient may indicate activity from these two clusters.
3. Nimbus Manticore actors likely expand infrastructure across Europe, Middle-East, and Asia
Summary
Nimbus Manticore (aka Tortoiseshell) is an Iranian-linked cyber espionage group primarily targeting defense and military organizations. Based on newly identified sub-domains, the group is likely expanding operations into Europe, the Middle East, and Asia through new infrastructure.
Category: Threat Actor Activities
Industry: Technology, Public Sector and Government Administration, Aviation
Sources
-
https://therecord.media/iran-linked-hackers-expand-infrastructure-europe-middle-east
-
https://www.group-ib.com/blog/tortoiseshell-apt-toolset-infrastructure/
-
https://securelist.com/mirage-kitten-new-tools/120811/?kaspr=5bet
-
https://unit42.paloaltonetworks.com/tracking-iran-apt-screening-serpens/
-
Internal OSec Research
Analyst comments
Researchers have identified new infrastructure associated with Tortoiseshell, an Iranian-linked espionage group active since at least 2018. The group primarily targets defense and technology organizations and has been seen targeting the aviation sector extensively. Recent findings include servers named uk1 and uk2 located in Britain, along with infrastructure in Belgium, Saudi Arabia, Japan, and the UAE. This suggests a broadening of both geographic reach and technical capabilities. Nimbus Manticore is linked to Iran’s Islamic Revolutionary Guard Corps and is recognized as one of the most active Iranian APT groups in 2026.
The group’s initial access vector is not confirmed for this campaign. Based on prior reporting, spear-phishing is the assessed primary delivery method, using lures tied to enticing job offers. This approach has been documented in their “Dream Job” campaign targeting the aviation and technology sectors. The group relies on DLL side-loading and search-order hijacking for stealth and persistence. In this campaign, the malicious DLL masquerades as the Windows Terminal Server SDK API (wtsapi32.dll), while forwarding legitimate function calls to the real wtsapi32.dll.
C2 operations use an SSH reverse tunnel. Prior intrusions used WebSockets as the primary communication channel. The actor favors Azure-hosted C2 endpoints (*.azurewebsites.net) to complicate network traffic analysis. This has been a consistent tactic since at least 2023.
Actionable guidance
The malware relies primarily on DLL side-loading. Monitoring for .DLL execution from directories other than standard Windows DLL locations (typically C:\Windows\System32) can identify potential abuse. Based on prior reporting, the threat actor delivers .ZIP archives containing .EXE and .DLL files as the initial payload stage. Scanning .ZIP attachments for these file types can block the initial intrusion. Lures typically impersonate job offers from well-known brands in the targeted sectors. The actor has also been observed linking to external sites such as OpenOffice to host the initial .ZIP payload. Additional indicators of compromise include repeated outbound connections to *.azurewebsites[.]net domains. Blocking the domain itself is unlikely to be a long-term solution as legitimate websites also use the primary domain, however a whitelist of known sites using the domain is likely a better alternative to outright blocking. If OpenOffice is not used for duties carried out during hours, then it can likely be blocked.