SynAck
SynAck is ransomware known since at least September 2017 and observed in April 2018 using Process Doppelgänging.
Profile source: Mallory opens in a new tabSynAck
Family profile
SynAck is ransomware known since at least September 2017 and observed in April 2018 using Process Doppelgänging. It encrypts victim machines and then demands ransom payment. Reported behaviors include enumerating Registry keys associated with event logs, manipulating Registry keys, clearing event logs, enumerating all running services, gathering usernames from infected hosts, and parsing export tables of system DLLs to locate and invoke Windows API functions. SynAck also performs language/keyboard-layout based geofencing: it uses the GetKeyboardLayoutList API to enumerate installed keyboard layouts, compares them against a hardcoded language code list, and if a match is found it sleeps for 300 seconds and exits without encrypting files. The provided content does not attribute SynAck to a specific threat actor or industry targeting, and no concrete IOCs are given.
Operational record
MITRE ATT&CK