Uptime Hamster: 10d 7h 0mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza ShadowSyndicate

ShadowSyndicate

0 incidentes 0 paises 0 sectores apt RU Ultimo: -
Ver en IntelTracker → APTTrail →
ShadowSyndicate, also identified as Infra Storm, emerged on July 16, 2022, operating primarily as a Ransomware-as-a-Service affiliate, though some analysis considers the possibility of them functioning as an initial access broker or bulletproof hosting provider. The group is assessed to be of Russian origin, with moderate confidence in state sponsorship, given connections found to Russian-linked hosting and potential ties to the Kremlin. Their primary motivation is financial gain through facilitating ransomware attacks for various groups . What distinguishes ShadowSyndicate is their unparalleled operational versatility and consistent use of unique Secure Shell (SSH) fingerprints across a large network of servers. They are known for working with numerous top-tier ransomware families, having been associated with at least seven different strains, and have recently evolved their infrastructure management to include a server transition technique, rotating SSH keys to evade tracking.
Tecnicas MITRE
T1588.002 - Tool, T1105 - Ingress Tool Transfer, T1573 - Encrypted Channel, T1486 - Data Encrypted for Impact, T1078, T1071.001
CVEs relacionadas
CVE-2024-1709, CVE-2024-1708, CVE-2023-4966, CVE-2023-34362, CVE-2022-42475
Tipo
apt
Pais origen
RU
Motivacion
-
Impacto
19
Actualizado
Sat, 24 Fe

Sectores objetivo (SOCRadar)

Information ServicesOtherOther Information ServicesData Processing, Hosting, and Related ServicesEngineering Services