Cybercrime cluster ShadowSyndicate has expanded its attack infrastructure while retaining OpenSSH use and launching the same access keys since its initial disclosure in 2023, according to Infosecurity Magazine.Two new SSH fingerprints linked to ShadowSyndicate that were discovered after overlaps between known and new infrastructure were observed indicated persistent coordination as part of the operation, a report from Group-IB showed. ShadowSyndicate also had at least 20 servers functioning as command-and-control nodes for open-source post-exploitation tools, red team frameworks, and other offensive tools. Even though such servers have been associated with multiple ransomware gangs, including Black Basta, Clop, and ALPHV/BlackCat, uncertainties regarding ShadowSyndicate's exact involvement in cybercrime remain."While it's still not possible yet to fully confirm the exact nature of ShadowSyndicate, Group-IB's current intelligence primarily points to the following options: either they operate as an Initial Access Broker (IAB) or offer bulletproof hosting (BPH) provider services," said researchers.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds




