Threat Intelligence

Augmented ShadowSyndicate cybercrime infrastructure uncovered

Hacked computer system showing a skull icon with lines of code, illustrating cybercrime, data protection issues, and malware

Cybercrime cluster ShadowSyndicate has expanded its attack infrastructure while retaining OpenSSH use and launching the same access keys since its initial disclosure in 2023, according to Infosecurity Magazine.

Two new SSH fingerprints linked to ShadowSyndicate that were discovered after overlaps between known and new infrastructure were observed indicated persistent coordination as part of the operation, a report from Group-IB showed. ShadowSyndicate also had at least 20 servers functioning as command-and-control nodes for open-source post-exploitation tools, red team frameworks, and other offensive tools. Even though such servers have been associated with multiple ransomware gangs, including Black Basta, Clop, and ALPHV/BlackCat, uncertainties regarding ShadowSyndicate's exact involvement in cybercrime remain.

"While it's still not possible yet to fully confirm the exact nature of ShadowSyndicate, Group-IB's current intelligence primarily points to the following options: either they operate as an Initial Access Broker (IAB) or offer bulletproof hosting (BPH) provider services," said researchers.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds