Ransomware Group intelligence
Synack
InactiveTrack Synack with 1 published victims and 1 known leak locations in a single intelligence view.
Overview
Synack is tracked by Breach House as a ransomware group with 1 published victims.
India is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 1h ago | xqkz2rmrqkeqf6sjbrb47jfwnqxcd4o2zvaxxzrpbh2piknms37rw2ad.onion |
Top Activity Sectors (1)
Typical Attacks (14)
▼How Synack typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via SynAck.
-
T1106 Native API Execution
What they do: SynAck parses the export tables of system DLLs to locate and call various Windows API functions.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
What they do: SynAck can manipulate Registry keys.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
What they do: SynAck abuses NTFS transactions to launch and conceal malicious processes.
What that means: Adversaries may inject malicious code into process via process doppelgänging in order to evade process-based defenses as well as possibly elevate privileges.
-
T1027 Obfuscated Files or Information Stealth
What they do: SynAck payloads are obfuscated prior to compilation to inhibit analysis and/or reverse engineering.
What that means: Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit.
-
What they do: SynAck checks its directory location in an attempt to avoid launching in a sandbox.
What that means: Adversaries may employ various system checks to detect and avoid virtualization and analysis environments.
-
T1685.005 Clear Windows Event Logs Defense Impairment
What they do: SynAck clears event logs.
What that means: Adversaries may clear Windows Event Logs to hide the activity of an intrusion.
-
T1007 System Service Discovery Discovery
What they do: SynAck enumerates all running services.
What that means: Adversaries may try to gather information about registered local system services.
-
T1012 Query Registry Discovery
What they do: SynAck enumerates Registry keys associated with event logs.
What that means: Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software.
-
T1033 System Owner/User Discovery Discovery
What they do: SynAck gathers user names from infected hosts.
What that means: Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system.
-
T1057 Process Discovery Discovery
What they do: SynAck enumerates all running processes.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1082 System Information Discovery Discovery
What they do: SynAck gathers computer names, OS version info, and also checks installed keyboard layouts to estimate if it has been launched from a certain list of countries.
What that means: An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
-
T1083 File and Directory Discovery Discovery
What they do: SynAck checks its directory location in an attempt to avoid launching in a sandbox.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1614.001 System Language Discovery Discovery
What they do: SynAck lists all the keyboard layouts installed on the victim’s system using GetKeyboardLayoutList API and checks against a hardcoded language code list.
What that means: Adversaries may attempt to gather information about the system language of a victim in order to infer the geographical location of that host.
-
T1486 Data Encrypted for Impact Impact
What they do: SynAck encrypts the victims machine followed by asking the victim to pay a ransom.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
Crypto Wallets (1)
▼| Address | Chain | Received (USD) | Payments |
|---|---|---|---|
15n6gV8QUBsy2yh7wqLppWG4Fw4gsUTNAj |
bitcoin | $491,052 | 496 |
Crowdsourced payment data from Ransomwhere, licensed CC BY 4.0. Figures are what has been reported and attributed to this family, not a confirmed total. Cite as: Cable, Jack. (2024). Ransomwhere: A Crowdsourced Ransomware Payment Dataset (1.1.0) [Data set]. Zenodo. https://doi.org/10.5281/zenodo.6512122
Victims (1)
Search, filter and paginate the victim timeline for Synack. Showing 1–1 of 1.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Maharashtra Industrial Development Corporation (MIDC) IT systems id591 View details | India | Manufacturing / Engineering | — | |
|
No additional victim description available. |
|||||