Our read, medium confidence: this toolkit belongs to a ransomware group or an initial access broker feeding one. Full breakdown, every module we received, and IOCs on the blog: expel.com/blog/synkloa... (7/7)
expel.com
SynkLoader: when you throw in everything but the kitchen sink
Discover a new malware family, SynkLoder. See how we reverse-engineered its phishing tactics to expose its attack chain.