logo

Dusting for fingerprints: ShadowSyndicate, a new RaaS player?

ID: 17081c31-471c-5833-9f3b-ea7e57072aa5

STIX ID: report--17081c31-471c-5833-9f3b-ea7e57072aa5

Feed Name: Group-IB Blog

Threat Score
78/100

Date Published: 2023-09-26

Date Updated: 2026-04-27

...
...

This Group-IB joint research identifies a suspected RaaS affiliate named ShadowSyndicate that has deployed the same SSH fingerprint (1ca4cbac895fc3bd12417b77fc6ed31d) across 85 servers since July 2022, with at least 52 used as Cobalt Strike C2s; investigators link the infrastructure to multiple ransomware families (ALPHV/BlackCat, Cl0p, Quantum, Nokoyawa, Royal, Play) and commodity tooling (Cobalt Strike, Sliver, IcedID, Matanbuchus), and provide a full list of IPs, Cobalt Strike watermarks, C2 configs, and correlations to aid attribution and hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.