logo

ShadowSyndicate Leverages Server Transition Technique in Latest Ransomware Attacks

ID: e20feb90-2808-58a7-8212-4b14ca6ecce0

STIX ID: report--e20feb90-2808-58a7-8212-4b14ca6ecce0

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-02-05

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

ShadowSyndicate is a sophisticated cybercrime cluster active as of February 2026 that uses a novel server-transition technique—rotating SSH fingerprints across clusters—to obscure operational continuity. Group-IB analysis links at least 20 C2 servers (running frameworks like Cobalt Strike, Metasploit, Havoc, Mythic, Sliver) to the actor, notes ties to multiple ransomware families (Cl0p/Truebot, ALPHV/BlackCat, Black Basta, Ryuk, Malsmoke), and provides observed IOCs (e.g., IP 46.161.27.151, SSH fingerprint 55c658703c07d6344e325ea26cf96c3b), while assessing the actor as a hybrid IAB/BPH provider with high sophistication and continued hostile activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.