ShadowSyndicate Using Server Transition Technique in Ransomware Attacks
ID: 78958929-7f1e-51b0-b056-965da05e3db8
STIX ID: report--78958929-7f1e-51b0-b056-965da05e3db8
Feed Name: cybersecurityNews.com
ShadowSyndicate, active since 2022, has evolved to rotate SSH keys across reused servers to hinder tracking; researchers identified multiple SSH fingerprints and at least 20 command-and-control servers deploying toolkits like Cobalt Strike, Havoc, Mythic, and others, with infrastructure linked to multiple ransomware groups (Cl0p, ALPHV/BlackCat, Black Basta, Ryuk, Malsmoke). The report provides SSH fingerprints and infrastructure correlation insights and recommends monitoring ASNs, IPs, repeated MFA failures, anomalous login sources, and rapid authentication attempts for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
