Also known as: tracked as, Jul 6, 2026, Bjorka, SkyWave, quic, Colddraw Ransomware, built a, OffSec, Lolkek, medium-sized, medium-sized bu, targeting nume, Dispossessor, active since August 2023, RA World, Raznatovic, Linux VMware, 54BB47h, Fonix, Abyss Locker, ARCrypter, GlobeImposter, CosmicBeetle, PlayCrypt, N13V, operated by UNC2190, FonixCrypter
0day Syndicate operates as a ransomware‑as‑a‑service platform that blends traditional phishing vectors with advanced techniques such as AI‑assisted reconnaissance and zero‑click malware delivery. The group distributes malicious URLs, HTA scripts, and ZIP archives to compromise victims’ infrastructure, exploiting known CVEs like CVE‑2026‑60137 and CVE‑2025‑68686 in industrial control systems, VMware Linux kernels, and web applications. Once inside, the actor stages stolen data for exfiltration via a dedicated data‑leak site while simultaneously deploying its flagship Babuk Locker 2.0 / Dispossessor ransomware to encrypt files. The dual approach—data theft + encryption—enables double‑extortion tactics that generate significant financial gains. Command and control is maintained through an IoT‑botnet loader layer using Mirai/Mozi frameworks, coupled with a custom chat‑portal API that allows negotiators to monitor compliance and adjust ransom demands dynamically. This architecture exemplifies the syndicate’s agile operational posture. The group’s portfolio includes auxiliary tools such as Infostealer variants (Dispossessor, win.stealc, win.coinminer), YARA rule generators for stealth detection, and a spectrum of industrial control exploits (PLC, Linux kernel, VMware vulnerabilities). Their global footprint spans the US, EU, Asia, and Brazil, with notable campaigns targeting healthcare, financial services, manufacturing, and critical infrastructure. The most recent incident on 28 May 2026 saw an attack on the Brazilian data‑intelligence firm DXON; the syndicate executed coordinated delivery, encrypted critical files, exfiltrated sensitive data, and issued a public leak threat. This operation showcased their swift execution coupled with psychological pressure tactics, emphasizing the group’s capacity for impactful, high‑profile attacks.
Objectives
Targeted Sectors
Targeted Countries / Regions
Executive Summary
0day Syndicate is a medium‑sophistication ransomware‑as‑a‑service group that has operated since August 2023, targeting a broad spectrum of industries across multiple countries. Their attacks combine zero‑click phishing delivery with opportunistic exploitation of industrial control and VMware Linux vulnerabilities, followed by data exfiltration and double‑extortion tactics. The syndicate leverages a botnet‑based C2 infrastructure, an online negotiation portal, and a custom Babuk‑derived ransomware variant to maximize profit while creating public‑domain leaks when ransoms are not paid. Their recent assault on the Brazilian firm DXON demonstrates swift execution, aggressive extortion messaging, and cross‑sector reach.
Goals & Targeting
0day Syndicate is primarily motivated by financial gain; it targets sectors that historically experience large ransom payouts—including healthcare, finance, manufacturing, critical infrastructure, transportation, energy, defense, telecommunications, education, and retail—across a wide array of countries (US, UK, Germany, France, Spain, Russia, Brazil, Canada, Australia, Iran). Their strategy is to exploit systems with high-value data or operational importance, leverage zero‑day or low‑exposure vulnerabilities in industrial control and virtualization environments, and use double‑extortion to pressure victims into paying. The actor’s RaaS model also indicates an intent to outsource delivery and negotiation, expanding its reach without increasing internal operational risk.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The syndicate exhibits a global, persistent operational tempo, with frequent monthly campaigns reported across South America, Europe, and North America. Victims span from mid‑sized enterprises to critical infrastructure providers, indicating a low barrier to entry but targeting high‑value data. A signature pattern is the combination of rapid malware deployment via compromised websites or malicious URLs, aggressive exploitation of known unpatched vulnerabilities (particularly in PLCs and VMware Linux), followed by exfiltration, public leak threats, and a negotiation chat channel that allows real‑time price adjustments. Notable historic operations include: attacks on Brazilian fraud prevention firm DXON (May 2026), Bulgarian publisher GoKids (2025) with similar data‑leak tactics, industrial control system breaches using Dispossessor to exploit PLC vulnerabilities, and widespread ransomware releases distributed via Mirai/Mozi loaders. The actor also shows flexibility in leveraging multiple toolchains—Babuk derivatives for encryption, Infostealer variants for credential theft—and adapting quickly to patching by modifying YARA signatures.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the described capabilities, tactics, and campaign patterns is high due to multiple independent reports, observed malware samples, and documented C2 infrastructure. However, gaps remain regarding the internal structure of the group (e.g., exact membership size, command hierarchy), precise attribution timeline prior to August 2023, and whether future variants will incorporate additional evasion techniques such as fileless execution. Consequently, ongoing monitoring of emerging indicators and intelligence updates is advised.
No observed data linked yet.
5
Techniques
50
Tools
5
Campaigns
41
IOCs
0
Observed Data
5
Tactics