Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors synack

Description

SynAck is a sophisticated ransomware operation first spotted in 2017, known for using hybrid ECIES encryption and the Doppelganging process injection technique to evade detection; in August 2021 the group rebranded as El_Cometa, transitioning to a full RaaS model and releasing master decryption keys for prior victims. Known victims: 1

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

SynAck is a sophisticated ransomware operation initially identified in 2017, later rebranding as El_Cometa in August 2021. Known for using hybrid ECIES encryption and Doppelganging process injection techniques to evade detection, SynAck operates with a focus on financial gain through ransomware activities. The group has transitioned to a ransomware-as-a-service (RaaS) model, offering master decryption keys to prior victims as part of their rebranding efforts.

Goals & Targeting

SynAck operates primarily with a goal of achieving financial gain through ransomware attacks. While specific targeted sectors and countries are not explicitly listed, such groups typically target industries with higher susceptibility to disruptions, often including healthcare, education, and critical infrastructure. The group's rebranding and shift to a RaaS model suggest an expansion in scope and targeting profile, aiming to increase both the scale and profitability of its operations.

Enhanced Description

SynAck, originally identified in 2017, emerged as a notable ransomware operation known for its technical sophistication. The group's use of hybrid ECIES encryption and the Doppelganging process injection technique highlights its efforts to evade detection and persist within targeted networks. In August 2021, SynAck rebranded itself as El_Cometa, marking a shift towards a full ransomware-as-a-service (RaaS) model. This transition included the release of master decryption keys for previous victims, possibly indicating an attempt to build trust or reposition itself in the cybercriminal landscape. The group's strategic focus remains centered on financial gain through ransomware activities, aligning with its criminal motivations.

Key Capabilities

  • Ransomware-as-a-Service (RaaS)
  • Hybrid ECIES encryption
  • Doppelganging process injection technique

MITRE ATT&CK Tactics

Exfiltration of data
Hijacking

ATT&CK Techniques

T1059.003
T1055

Campaigns & Victims

SynAck's campaign patterns involve targeted ransomware attacks leveraging sophisticated techniques to evade detection and persist within networks. Known victims are limited, but the group's history suggests a focus on high-value targets that can generate significant financial returns. The rebranding to El_Cometa in 2021 indicates an evolution in operational strategy, including the release of decryption keys for prior victims, which may aim to reduce victim backlash and encourage further cooperation. Campaigns typically demonstrate a focus on lateral movement within networks and persistence techniques.

IOC Patterns

  • Spear-phishing emails with malicious links or attachments
  • Encrypted files (common extensions like .synacked or others)
  • Doppelganging process injection indicators

Recommended Actions

  • Implement robust backup strategies to ensure data integrity and quick recovery from ransomware attacks.
  • Educate employees about phishing attempts and suspicious email activities.
  • Monitor network traffic for signs of lateral movement and encrypted processes indicative of Doppelganging technique usage.

Suggested Tags

ransomware
APT

Confidence Assessment

Low confidence in the available data due to limited information on specific campaigns, targets beyond one known victim, and lack of detailed TTPs. The rebranding as El_Cometa introduces additional uncertainty about their current operational strategies.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
ransomware
APT

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Mar 21, 2021
Last Seen
Mar 21, 2021
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.