SynAck is a sophisticated ransomware operation first spotted in 2017, known for using hybrid ECIES encryption and the Doppelganging process injection technique to evade detection; in August 2021 the group rebranded as El_Cometa, transitioning to a full RaaS model and releasing master decryption keys for prior victims. Known victims: 1
Objectives
Executive Summary
SynAck is a sophisticated ransomware operation initially identified in 2017, later rebranding as El_Cometa in August 2021. Known for using hybrid ECIES encryption and Doppelganging process injection techniques to evade detection, SynAck operates with a focus on financial gain through ransomware activities. The group has transitioned to a ransomware-as-a-service (RaaS) model, offering master decryption keys to prior victims as part of their rebranding efforts.
Goals & Targeting
SynAck operates primarily with a goal of achieving financial gain through ransomware attacks. While specific targeted sectors and countries are not explicitly listed, such groups typically target industries with higher susceptibility to disruptions, often including healthcare, education, and critical infrastructure. The group's rebranding and shift to a RaaS model suggest an expansion in scope and targeting profile, aiming to increase both the scale and profitability of its operations.
Enhanced Description
SynAck, originally identified in 2017, emerged as a notable ransomware operation known for its technical sophistication. The group's use of hybrid ECIES encryption and the Doppelganging process injection technique highlights its efforts to evade detection and persist within targeted networks. In August 2021, SynAck rebranded itself as El_Cometa, marking a shift towards a full ransomware-as-a-service (RaaS) model. This transition included the release of master decryption keys for previous victims, possibly indicating an attempt to build trust or reposition itself in the cybercriminal landscape. The group's strategic focus remains centered on financial gain through ransomware activities, aligning with its criminal motivations.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Campaigns & Victims
SynAck's campaign patterns involve targeted ransomware attacks leveraging sophisticated techniques to evade detection and persist within networks. Known victims are limited, but the group's history suggests a focus on high-value targets that can generate significant financial returns. The rebranding to El_Cometa in 2021 indicates an evolution in operational strategy, including the release of decryption keys for prior victims, which may aim to reduce victim backlash and encourage further cooperation. Campaigns typically demonstrate a focus on lateral movement within networks and persistence techniques.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Low confidence in the available data due to limited information on specific campaigns, targets beyond one known victim, and lack of detailed TTPs. The rebranding as El_Cometa introduces additional uncertainty about their current operational strategies.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics