Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors the syndicate

Also known as: tracked as, SilverTerrier, TA577, in turn, operators, known for compromising, 911 emergency servic, port, TA551, Grim Spider, injection targets, TEMP.MixMaster, GOLD ULRICK, Shakthak, ATK236, G0127, Monster Libra

Description

The Syndicate, also identified as SilverTerrier or TA577, operates a sophisticated cybercrime ecosystem that blends classic phishing with supply‑chain masquerading and mobile malware. Initial access is often achieved through spearphishing emails containing malicious documents that install IcedID or other trojans, which subsequently deploy Cobalt Strike infrastructure for lateral movement and tool transfer. This foothold enables the delivery of ransomware families such as Conti via the Shathak (TA551) variant, yielding direct financial gains. Beyond ransomware, the Syndicate aggressively targets payment‑card credential theft, leveraging fake Android apps and OTP interception to hijack contactless payments. Their asset smuggling capabilities—shipping stolen iPhones and luxury goods—are coordinated through Telegram channels that also recruit money and product mules for cross‑border transport and laundering. The group's operations are marked by an aggressive tempo: campaigns hit hundreds of thousands of companies, continually rotating newly created domains and IP addresses to evade detection. Law‑enforcement interventions (e.g., Operation Delilah, Falcon I/II) have seized parts of their infrastructure, yet new phishing vectors and malware variants continue to surface. Overall, the Syndicate exhibits a modular and adaptive threat model, blending technical sophistication with social engineering and physical logistics to maximize illicit revenue streams across diverse industries.

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Financial services
Retail
Defense
Telecommunications
Pharmaceutical
Government
Manufacturing
Media
Healthcare
Transportation
Utilities
Food agriculture
Information technology
Critical infrastructure
Mining

Targeted Countries / Regions

SG
CN
NG
US
GB
AU
JP
CA
RU
UA
IT

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 day ago

Executive Summary

The Syndicate is a medium‑sophistication criminal group that runs large‑scale phishing and BEC campaigns to infiltrate over 500 000 organizations worldwide, deploying malicious documents to deliver ransomware such as Conti via Shathak (TA551). In addition to ransomware, the organization harvests payment‑card data, smuggles stolen devices, and launders profits through cross‑border transport operations managed on Telegram. Their operations span all major sectors—including finance, retail, health, defense, and critical infrastructure—across more than 150 countries.

Goals & Targeting

The primary objective of The Syndicate is monetary gain, accomplished through three interconnected channels: ransomware extortion (Conti, Shathak), credentialed payment‑card theft, and smuggling/laundering of high‑value goods. Their targeting is intentionally broad, encompassing financial services, retail, telecommunications, defense, pharmaceuticals, government entities, manufacturing, media, healthcare, transportation, utilities, food‑agriculture, IT, and critical infrastructure worldwide—especially in countries where regulatory enforcement may be uneven or fragmented.

Enhanced Description

Key Capabilities

  • Large‑scale worldwide phishing and BEC campaigns targeting over 500 000 organizations
  • Initial access via malicious document attachments delivering malware such as IcedID, Shathak (TA551), and other RATs
  • Deployment of Cobalt Strike infrastructure for lateral movement and tool transfer
  • Delivery of ransomware families like Conti through compromised infrastructure
  • Supply‑chain style attacks embedding malware in purchase orders, product inquiries, and COVID‑19 aid emails
  • Phishing targeting payment card and OTP credentials, including use of burn‑phone mules to hijack contactless payments
  • Use of remote access trojans (CraxsRAT, Remcos, AsyncRAT) for device takeover and credential theft
  • Asset smuggling, money laundering and cross‑border transport operations coordinated via Telegram channels

MITRE ATT&CK Tactics

Initial Access
Credential Access
Execution
Lateral Movement
Command & Control

ATT&CK Techniques

T1566
T1566.001
T1566.002
T1605
T1021

Software / Tooling

Cobalt Strike
IcedID
Shathak (TA551)
TR Botnet (TA577)
CraxsRAT
Remcos
AsyncRAT
SugarGh0st RAT
PupyRAT

Campaigns & Victims

The Syndicate’s campaigns are characterized by high throughput phishing, often deploying millions of spearphishing emails with malicious attachments or fake Android app downloads. Success rates appear to remain high due to the use of fresh domains and IPs, allowing rapid pivoting between victims. Targeted industries include both critical infrastructure and consumer‑facing sectors, reflecting a strategy that values both immediate extortion gains from ransomware and longer‑term revenue streams from payment‑card theft and physical smuggling operations. Recent publicized incidents—such as the Onslow North Carolina water attack, the Dataresolution.net MSP compromise, and 2023 fake Android app campaigns—highlight an operational tempo that averages multiple attacks per month across continents. Law‑enforcement disruptions have occasionally isolated segments of their infrastructure; however, residual operations continue to emerge, indicating a resilient supply‑chain and modular malware distribution model.

IOC Patterns

  • Domain names of newly created Cobalt Strike‑related infrastructure
  • IP addresses used for command-and-control servers
  • Malicious document attachments in spearphishing emails
  • Phishing emails with fake Android app downloads
  • Compromised legitimate software update files
  • Telegram channels for mule recruitment

Recommended Actions

  • Implement comprehensive phishing and BEC awareness training for employees and third‑party vendors
  • Deploy email filtering, attachment sandboxing, and advanced threat detection to block malicious documents and fake mobile apps
  • Detect and block Cobalt Strike beacon traffic and lateral-tool transfer communications
  • Block or monitor newly registered domains and IP addresses linked to the Syndicate’s infrastructure
  • Enable endpoint protection with signatures for IcedID, Shathak (TA551), and other ransomware indicators
  • Monitor network activity for RAT usage such as CraxsRAT, Remcos, AsyncRAT, and block lateral movement pathways
  • Enforce multi‑factor authentication and monitor OTP interception attempts
  • Verify supply‑chain communications and validate purchase order authenticity to detect malicious file injections
  • Conduct asset tracking audits to identify smuggling or unauthorized device activation patterns

Suggested Tags

Phishing
Business Email Compromise
Cobalt Strike
IcedID
Shathak (TA551)
TR Botnet (TA577)
Conti Ransomware
Large-Scale Phishing Syndicate
International Cybercrime
Financially Motivated
Malicious Documents
Remote Access Trojan
Android App Malware
Money Laundering Mule
Telegram Recruitment
Syndicate Fraud
Credential Theft
OTP Interception
Supply Chain Attack

Confidence Assessment

Confidence in the primary attributes of The Syndicate is high, supported by multiple open‑source reports and documented incidents involving ransomware delivery and phishing campaigns. However, gaps remain regarding specific attribution evidence for all malware variants mentioned, precise timelines of operator activity, and the full extent of their logistics network. Further intelligence focusing on infrastructure mapping, economic impact assessment, and insider testimonies would improve certainty.

ATT&CK Techniques

Software / Tooling

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 14 IPv4 Address 6

References

  1. www.group-ib.com — Cited by web research for: SilverTerrier
  2. www.esentire.com — Cited by web research for: TA577
  3. www.group-ib.com — Cited by web research for: T1021
  4. securelist.com — Cited by web research for: Dark
  5. www.recordedfuture.com — Cited by web research for: Leverage
  6. www.cyber.gov.au — Cited by web research for: curl
  7. https://odin.t2com.army.mil/DATE/bdcaa2c39c08dea6b74187c8af3bdc93 — Cited by AI analysis.

Intel Summary

5

Techniques

48

Tools

2

Campaigns

28

IOCs

0

Observed Data

3

Tactics

Tags

Phishing
Business Email Compromise
Cobalt Strike
IcedID
Shathak (TA551)
TR Botnet (TA577)
Conti Ransomware
Large-Scale Phishing Syndicate
International Cybercrime
Financially Motivated
Malicious Documents
Remote Access Trojan
Android App Malware
Money Laundering Mule
Telegram Recruitment
Syndicate Fraud
Credential Theft
OTP Interception
Supply Chain Attack

Details

Type
Criminal
Sophistication
Medium
Resource Level
Unknown
Primary Motivation
Organizational gain
Country of Origin
China (CN)
Confidence
80%
Added
Jul 15, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.