Also known as: tracked as, SilverTerrier, TA577, in turn, operators, known for compromising, 911 emergency servic, port, TA551, Grim Spider, injection targets, TEMP.MixMaster, GOLD ULRICK, Shakthak, ATK236, G0127, Monster Libra
The Syndicate, also identified as SilverTerrier or TA577, operates a sophisticated cybercrime ecosystem that blends classic phishing with supply‑chain masquerading and mobile malware. Initial access is often achieved through spearphishing emails containing malicious documents that install IcedID or other trojans, which subsequently deploy Cobalt Strike infrastructure for lateral movement and tool transfer. This foothold enables the delivery of ransomware families such as Conti via the Shathak (TA551) variant, yielding direct financial gains. Beyond ransomware, the Syndicate aggressively targets payment‑card credential theft, leveraging fake Android apps and OTP interception to hijack contactless payments. Their asset smuggling capabilities—shipping stolen iPhones and luxury goods—are coordinated through Telegram channels that also recruit money and product mules for cross‑border transport and laundering. The group's operations are marked by an aggressive tempo: campaigns hit hundreds of thousands of companies, continually rotating newly created domains and IP addresses to evade detection. Law‑enforcement interventions (e.g., Operation Delilah, Falcon I/II) have seized parts of their infrastructure, yet new phishing vectors and malware variants continue to surface. Overall, the Syndicate exhibits a modular and adaptive threat model, blending technical sophistication with social engineering and physical logistics to maximize illicit revenue streams across diverse industries.
Objectives
Targeted Sectors
Targeted Countries / Regions
Executive Summary
The Syndicate is a medium‑sophistication criminal group that runs large‑scale phishing and BEC campaigns to infiltrate over 500 000 organizations worldwide, deploying malicious documents to deliver ransomware such as Conti via Shathak (TA551). In addition to ransomware, the organization harvests payment‑card data, smuggles stolen devices, and launders profits through cross‑border transport operations managed on Telegram. Their operations span all major sectors—including finance, retail, health, defense, and critical infrastructure—across more than 150 countries.
Goals & Targeting
The primary objective of The Syndicate is monetary gain, accomplished through three interconnected channels: ransomware extortion (Conti, Shathak), credentialed payment‑card theft, and smuggling/laundering of high‑value goods. Their targeting is intentionally broad, encompassing financial services, retail, telecommunications, defense, pharmaceuticals, government entities, manufacturing, media, healthcare, transportation, utilities, food‑agriculture, IT, and critical infrastructure worldwide—especially in countries where regulatory enforcement may be uneven or fragmented.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The Syndicate’s campaigns are characterized by high throughput phishing, often deploying millions of spearphishing emails with malicious attachments or fake Android app downloads. Success rates appear to remain high due to the use of fresh domains and IPs, allowing rapid pivoting between victims. Targeted industries include both critical infrastructure and consumer‑facing sectors, reflecting a strategy that values both immediate extortion gains from ransomware and longer‑term revenue streams from payment‑card theft and physical smuggling operations. Recent publicized incidents—such as the Onslow North Carolina water attack, the Dataresolution.net MSP compromise, and 2023 fake Android app campaigns—highlight an operational tempo that averages multiple attacks per month across continents. Law‑enforcement disruptions have occasionally isolated segments of their infrastructure; however, residual operations continue to emerge, indicating a resilient supply‑chain and modular malware distribution model.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the primary attributes of The Syndicate is high, supported by multiple open‑source reports and documented incidents involving ransomware delivery and phishing campaigns. However, gaps remain regarding specific attribution evidence for all malware variants mentioned, precise timelines of operator activity, and the full extent of their logistics network. Further intelligence focusing on infrastructure mapping, economic impact assessment, and insider testimonies would improve certainty.
Onslow, North Carolina water
No observed data linked yet.
5
Techniques
48
Tools
2
Campaigns
28
IOCs
0
Observed Data
3
Tactics