SynAck
MITRE ATT&CK: S0242 View on attack.mitre.org
Aliases: Syn Ack, SynAck
- First seen
- 2017-09-01 00:00:00
- Malware type
- ransomware, trojan
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 15:43:21
Targeted industries: financial-services government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:us country_code:gb country_code:ca
Context
SynAck is variant of Trojan ransomware targeting mainly English-speaking users since at least fall 2017.
Detection coverage
- 302 Sigma rules
Malware & tools used
- File and Directory Discovery (attack-pattern)
- Modify Registry (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- System Checks (attack-pattern)
- System Information Discovery (attack-pattern)
- Process Doppelgänging (attack-pattern)
- Native API (attack-pattern)
- Query Registry (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- System Service Discovery (attack-pattern)
- Clear Windows Event Logs (attack-pattern)
- System Language Discovery (attack-pattern)
- Process Discovery (attack-pattern)
Reports & references
- bleepingcomputer.com — Synack Ransomware Sees Huge Spike In Activity (report)
- bleepingcomputer.com — Synack Ransomware Uses Process Doppelg Nging Technique (report)
- id-ransomware.blogspot.com — Synack Ransomware (report)
- zdnet.com — Synack Ransomware Group Releases Decryption Keys As They Rebrand To El Cometa (report)
- Kaspersky — 85431 (report)
- therecord.media — Synack Ransomware Gang Releases Decryption Keys For Old Victims (report)
- ransomlook.io — Synack (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Synack (report)
- MITRE ATT&CK — S0242 (report)
- usa.kaspersky.com — 2018 Synack Doppelganging (report)