Skip to content

SynAck

SynAck is a Windows ransomware family and associated criminal operation first observed in 2017.

Profile source: Mallory opens in a new tab

SynAck

Family profile

SynAck is a Windows ransomware family and associated criminal operation first observed in 2017. It encrypts victim files and systems and then demands payment for decryption. The malware is notable for early adoption of process doppelgänging as an evasion technique, making it one of the first ransomware strains publicly documented using that method to bypass security controls.

SynAck performs substantial host discovery before or during encryption. Documented behaviors include enumerating running processes and services, collecting the current username, and querying or modifying Windows Registry data, including event log-related keys. It also clears event logs, indicating an effort to reduce forensic visibility and hinder incident response. The malware dynamically resolves Windows API functions by parsing export tables of system DLLs, a technique consistent with defense evasion and reduced static detectability.

A characteristic targeting control in SynAck is its language and keyboard-layout filtering. It enumerates installed keyboard layouts through Windows APIs and compares them against a hardcoded exclusion list. If a match is found, the malware delays and exits without encrypting files, reflecting geofencing behavior commonly used to avoid infecting systems in selected regions.

SynAck has been associated with a ransomware group that later rebranded as El_Cometa. During that transition, the operators released master decryption keys covering victims infected from 2017 into early 2021, effectively ending the older SynAck operation. The group reportedly moved from a limited partner model toward a broader ransomware-as-a-service structure under the El_Cometa name.

SynAck targeted Windows environments and fits the broader pattern of financially motivated ransomware intrusions that combine host reconnaissance, anti-forensics, regional exclusion logic, and encryption-based extortion.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Extortion
  • Reconnaissance

Operational record

1
YARA rules
1
Leak sites
0 available

MITRE ATT&CK

SynAck in ATT&CK

15 distinct techniques

Reporting

Research mentioning SynAck

Mar 22
Sentinelone Labs Subdomain

Multi-Platform SMAUG RaaS Aims To See Off Competitors - SentinelLabs

SMAUG is a ransomware-as-a-service (RaaS) operation that advertises 64-bit payloads for Windows, Linux, and macOS, positioning itself as a multi-platform option for affiliates. The service reportedly charges a 20% affiliate fee plus a 0.2 BTC registration fee, and provides a web-based campaign builder, customizable ransom demands, offline encryption, and a "Company Mode" that allows a single decryption key to unlock multiple systems inside one targeted organization. Victims are directed to a Tor-based payment portal, while operators reportedly offer automated support for both affiliates and victims and bar attacks against CIS countries. On Windows, SMAUG uses obfuscated Go binaries that gather system details and stored browser credentials, establish persistence through Registry Run Keys consistent with MITRE ATT&CK T1547.001, and then encrypt files for impact using AES-256 with keys protected by RSA-2048, aligning with T1486 Data Encrypted for Impact tradecraft. The combination of credential collection, registry-based autostart, and hybrid cryptography reflects a mature ransomware model designed to support repeatable intrusions and broad enterprise targeting across multiple operating systems.

Aug 13
The Record Media

SynAck ransomware gang releases decryption keys for old victims | The Record from Recorded Future News

The operators behind SynAck ransomware, later rebranded as El_Cometa, released master decryption keys for victims infected from July 2017 through early 2021, allowing recovery of files from older attacks. A person claiming to be a former SynAck member provided the keys to The Record, and malware analyst Michael Gillespie of Emsisoft verified them by successfully decrypting data from prior incidents. Emsisoft said it would publish a safer public decryptor rather than have victims rely directly on leaked materials, and later released a SynAck decryption tool. SynAck had been known as a targeted ransomware operation that used advanced evasion methods, including Process Doppelgänging, heavy obfuscation, dynamic API resolution, sandbox checks, and country-based filtering to avoid analysis and detection. Researchers previously reported that the malware encrypted files with AES-256 while using an ECIES-like key protection scheme, terminated processes and backup-related services such as VSS, and cleared Windows event logs to hinder recovery and investigation. The gang said it disclosed the old keys after winding down the original SynAck operation and shifting to a broader ransomware-as-a-service model under the El_Cometa name.

Sep 2
Eset Welivesecurity

KryptoCibule: The multitasking multicurrency cryptostealer

ESET disclosed KryptoCibule, a previously undocumented malware family active since at least late 2018 that primarily targeted users in Czechia and Slovakia through malicious torrents posing as cracked software installers. The malware combined several cryptocurrency-focused functions: it mined coins on infected systems, monitored the clipboard to replace copied wallet addresses and redirect payments, searched for cryptocurrency wallets and related files for exfiltration, and also exposed remote-access trojan (RAT) capabilities. The campaign relied heavily on Tor and BitTorrent infrastructure and either bundled or fetched legitimate tools including Tor, Transmission, Apache httpd, and Buru SFTP Server to support command-and-control and data theft through onion services hosted on compromised machines. ESET said KryptoCibule used layered evasion and persistence measures, including obfuscation, masquerading as Adobe Reader components, scheduled tasks, Windows Defender exclusions, firewall rule changes, and checks for analysis tools and antivirus products; although only hundreds of victims were observed, the malware remained active and continued to gain new capabilities.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.