ShadowSyndicate
0 incidentes
0 paises
0 sectores
apt RU Ultimo: -
ShadowSyndicate, also identified as Infra Storm, emerged on July 16, 2022, operating primarily as a Ransomware-as-a-Service affiliate, though some analysis considers the possibility of them functioning as an initial access broker or bulletproof hosting provider. The group is assessed to be of Russian origin, with moderate confidence in state sponsorship, given connections found to Russian-linked hosting and potential ties to the Kremlin. Their primary motivation is financial gain through facilitating ransomware attacks for various groups . What distinguishes ShadowSyndicate is their unparalleled operational versatility and consistent use of unique Secure Shell (SSH) fingerprints across a large network of servers. They are known for working with numerous top-tier ransomware families, having been associated with at least seven different strains, and have recently evolved their infrastructure management to include a server transition technique, rotating SSH keys to evade tracking.
Sectores objetivo (SOCRadar)
Information ServicesOtherOther Information ServicesData Processing, Hosting, and Related ServicesEngineering Services