Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors 0day syndicate

Also known as: tracked as, Jul 6, 2026, Bjorka, SkyWave, quic, Colddraw Ransomware, built a, OffSec, Lolkek, medium-sized, medium-sized bu, targeting nume, Dispossessor, active since August 2023, RA World, Raznatovic, Linux VMware, 54BB47h, Fonix, Abyss Locker, ARCrypter, GlobeImposter, CosmicBeetle, PlayCrypt, N13V, operated by UNC2190, FonixCrypter

Description

0day Syndicate operates as a ransomware‑as‑a‑service platform that blends traditional phishing vectors with advanced techniques such as AI‑assisted reconnaissance and zero‑click malware delivery. The group distributes malicious URLs, HTA scripts, and ZIP archives to compromise victims’ infrastructure, exploiting known CVEs like CVE‑2026‑60137 and CVE‑2025‑68686 in industrial control systems, VMware Linux kernels, and web applications. Once inside, the actor stages stolen data for exfiltration via a dedicated data‑leak site while simultaneously deploying its flagship Babuk Locker 2.0 / Dispossessor ransomware to encrypt files. The dual approach—data theft + encryption—enables double‑extortion tactics that generate significant financial gains. Command and control is maintained through an IoT‑botnet loader layer using Mirai/Mozi frameworks, coupled with a custom chat‑portal API that allows negotiators to monitor compliance and adjust ransom demands dynamically. This architecture exemplifies the syndicate’s agile operational posture. The group’s portfolio includes auxiliary tools such as Infostealer variants (Dispossessor, win.stealc, win.coinminer), YARA rule generators for stealth detection, and a spectrum of industrial control exploits (PLC, Linux kernel, VMware vulnerabilities). Their global footprint spans the US, EU, Asia, and Brazil, with notable campaigns targeting healthcare, financial services, manufacturing, and critical infrastructure. The most recent incident on 28 May 2026 saw an attack on the Brazilian data‑intelligence firm DXON; the syndicate executed coordinated delivery, encrypted critical files, exfiltrated sensitive data, and issued a public leak threat. This operation showcased their swift execution coupled with psychological pressure tactics, emphasizing the group’s capacity for impactful, high‑profile attacks.

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Healthcare
Financial services
Manufacturing
Government
Construction
Critical infrastructure
Food agriculture
Defense
Transportation
Energy
Oil gas
Hospitality
Education
Telecommunications
Retail
Information technology

Targeted Countries / Regions

US
BR
CN
GB
RU
NL
PK
CA
AU
FR
IL
IR

AI Analysis

Grounded in web research
· analyzed in 5 chunks · 4 days ago

Executive Summary

0day Syndicate is a medium‑sophistication ransomware‑as‑a‑service group that has operated since August 2023, targeting a broad spectrum of industries across multiple countries. Their attacks combine zero‑click phishing delivery with opportunistic exploitation of industrial control and VMware Linux vulnerabilities, followed by data exfiltration and double‑extortion tactics. The syndicate leverages a botnet‑based C2 infrastructure, an online negotiation portal, and a custom Babuk‑derived ransomware variant to maximize profit while creating public‑domain leaks when ransoms are not paid. Their recent assault on the Brazilian firm DXON demonstrates swift execution, aggressive extortion messaging, and cross‑sector reach.

Goals & Targeting

0day Syndicate is primarily motivated by financial gain; it targets sectors that historically experience large ransom payouts—including healthcare, finance, manufacturing, critical infrastructure, transportation, energy, defense, telecommunications, education, and retail—across a wide array of countries (US, UK, Germany, France, Spain, Russia, Brazil, Canada, Australia, Iran). Their strategy is to exploit systems with high-value data or operational importance, leverage zero‑day or low‑exposure vulnerabilities in industrial control and virtualization environments, and use double‑extortion to pressure victims into paying. The actor’s RaaS model also indicates an intent to outsource delivery and negotiation, expanding its reach without increasing internal operational risk.

Enhanced Description

Key Capabilities

  • Data exfiltration via dedicated leak sites
  • Ransomware encryption using custom Babuk variant (Dispossessor)
  • Zero‑click phishing delivery through malicious URLs/HTA/ZIP files
  • Dual‑extortion strategy combining threat of data leak and file lockout
  • Botnet C2 leveraging Mirai/Mozi loaders
  • Online negotiation chat portal/API
  • Exploitation of PLC, Linux kernel, VMware vulnerabilities
  • Use of AI‑assisted reconnaissance for target selection
  • YARA rule development for malware detection
  • SQL injection, LDAP injection, XSS in web applications
  • Unauthorized token claims via OIDC manipulation
  • Privilege escalation through Microsoft token exchange misconfigurations
  • Industrial control system targeting (PLC, SCADA)

MITRE ATT&CK Tactics

Initial Access
Collection
Exfiltration
Impact
CommandandControl

ATT&CK Techniques

T1566.001
T1486
T1041
T1071
T1074

Software / Tooling

0day Syndicate Ransomware
YARA
Infostealer
Dispossessor
Mirai
Mozi
RemusStealer
win.stealc
win.coinminer
py.venus_stealer
win.salatstealer
elf.kuiper
Quic ransomware
Radiant
Radar (Dispossessor)
RA Group (RA World)
RANSOMED.VC / Raznatovic
Babuk

Campaigns & Victims

The syndicate exhibits a global, persistent operational tempo, with frequent monthly campaigns reported across South America, Europe, and North America. Victims span from mid‑sized enterprises to critical infrastructure providers, indicating a low barrier to entry but targeting high‑value data. A signature pattern is the combination of rapid malware deployment via compromised websites or malicious URLs, aggressive exploitation of known unpatched vulnerabilities (particularly in PLCs and VMware Linux), followed by exfiltration, public leak threats, and a negotiation chat channel that allows real‑time price adjustments. Notable historic operations include: attacks on Brazilian fraud prevention firm DXON (May 2026), Bulgarian publisher GoKids (2025) with similar data‑leak tactics, industrial control system breaches using Dispossessor to exploit PLC vulnerabilities, and widespread ransomware releases distributed via Mirai/Mozi loaders. The actor also shows flexibility in leveraging multiple toolchains—Babuk derivatives for encryption, Infostealer variants for credential theft—and adapting quickly to patching by modifying YARA signatures.

IOC Patterns

  • Domain indicator (e.g., dxon.com.br, ransomware.live)
  • Phishing link indicator via malicious URLs
  • Data leak site references

Recommended Actions

  • Implement and test regular off‑site backups to reduce impact of encryption
  • Deploy data exfiltration detection controls focusing on outbound large file transfers
  • Monitor for unauthorized remote administration tools and patch exposed services; harden endpoint security with EDR/EDR solutions
  • Conduct staff training programs focused on zero‑click phishing reconnaissance and suspicious URL handling
  • Enforce strict network segmentation especially around industrial control systems and VMware environments
  • Patch critical CVEs such as CVE‑2026‑60137, CVE‑2025‑68686 immediately
  • Detect and block C2 traffic by monitoring typical outbound protocols (HTTP/HTTPS, DNS) and anomalous patterns

Suggested Tags

ransomware
data exfiltration
phishing
AI-assisted ransomware
financially motivated
infostealer
data-leak-site
yara-detector
cve exploitation
industrial control
vmware vulnerability
PLC exploitation
iot botnet
mirai
mozi
double extortion
single extortion
raaS
custom ransomware variant

Confidence Assessment

Confidence in the described capabilities, tactics, and campaign patterns is high due to multiple independent reports, observed malware samples, and documented C2 infrastructure. However, gaps remain regarding the internal structure of the group (e.g., exact membership size, command hierarchy), precise attribution timeline prior to August 2023, and whether future variants will incorporate additional evasion techniques such as fileless execution. Consequently, ongoing monitoring of emerging indicators and intelligence updates is advised.

ATT&CK Techniques

Collection
1 technique
Command & Control
1 technique
Exfiltration
1 technique
Initial Access
1 technique

Software / Tooling

Campaigns / Victims

Observed Data

No observed data linked yet.

References

  1. www.ransomware.live — Cited by web research for: Bjorka
  2. www.dexpose.io — Cited by web research for: Payload
  3. vigil-osint.com — Cited by web research for: Mozi
  4. www.galaxywarden.com — Cited by web research for: Qilin
  5. www.legal-isac.org — Cited by web research for: Healthcare
  6. www.ransomware.live — Cited by web research for: ransomware.live
  7. https://ransomwhere.org/groups — Cited by AI analysis.
  8. https://socradar.io/free-tools/ransomware-intelligence/victims/dxon-com-br-0day-syndicate-0cbf6da1 — Cited by AI analysis.
  9. http://163.142.92.217:51284/i — Cited by AI analysis.
  10. http://219.157.49.205:54921/i — Cited by AI analysis.
  11. http://110.37.53.25:46551/i — Cited by AI analysis.
  12. http://59.97.254.151:40167/bin.sh — Cited by AI analysis.
  13. https://pdf-bro.lat/files/pdf-bro.lat/fcd598f9c282fd5b/DOC-9M8ORG.zip — Cited by AI analysis.
  14. http://115.49.25.217:34345/i — Cited by AI analysis.
  15. https://urlhaus.abuse.ch/blockpage/54BB47h — Cited by AI analysis.

Intel Summary

5

Techniques

50

Tools

5

Campaigns

41

IOCs

0

Observed Data

5

Tactics

Tags

Criminal
Ransomware
Financial gain
Medium sophistication
Zero-Day Exploitation
ransomware
data exfiltration
phishing
AI-assisted ransomware
financially motivated
infostealer
data-leak-site
yara-detector
cve exploitation
industrial control
vmware vulnerability
PLC exploitation
iot botnet
mirai
mozi
double extortion
single extortion
raaS
custom ransomware variant

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Country of Origin
China (CN)
Confidence
80%
Last Seen
May 29, 2026
Added
May 28, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.