An advanced, multilingual malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with a slew of novel features.

August 24, 2026

A sophisticated malware family has emerged onto the cyberthreat scene that might foreshadow ransomware attacks that are more successful than usual.

Marcus Hutchins and his colleagues at Expel that discovered it named the malware "SynkLoader," since it throws so many ideas ("everything but the kitchen sink") at trying to sneakily dig into corporate systems. It uses some conventional strategies — like executing code in-memory, running a scheduled task, etc. — but layers on a few interesting, novel tactics that make social engineering particularly compelling, and malware analysis especially frustrating.

The program is new, and how its creators intend to use it remains a mystery. But evidence in the code suggests that it might be the baby of a ransomware group or initial access broker (IAB), used to set the stage for follow-on ransomware.