- Joined
- Jan 22, 2026
- Messages
- 101
- Reaction score
- 923
One wrong move, and the scheme began to fall apart at the seams.

Behind the scenes of many extortion attacks, there remains an invisible but important part of the cybercrime ecosystem — the infrastructure that helps attackers quickly deploy tools and change platforms. The new analysis of Group-IB shows that the ShadowSyndicate activity cluster continues to evolve, maintaining recognizable technical habits and at the same time making it more difficult to mask connections between servers.
ShadowSyndicate combines different campaigns by intersecting infrastructure. The authors of the report note that cluster members actively use OpenSSH and usually rely on repeated SSH fingerprints, which allow connecting a large number of servers. Earlier, Group-IB described one of these prints, and the Intrinsec team later reported another similar one. In the new work, Group-IB confirms two additional SSH fingerprints, which also repeatedly occurred on different nodes and formed separate server clusters.
A key new observation was the tactic of reusing the already used infrastructure with the transfer of servers between "SSH clusters". Outwardly, this may look like a normal change of ownership, but operational security errors led to an intersection of keys and helped to prove the connection between the "old" and "new" use of resources. According to Group-IB estimates, at least two dozen servers were used as control nodes for various frameworks.
The detected infrastructure contained traces of toolkits that are often found in post-initial penetration attacks, including Cobalt Strike, Metasploit, Havoc, Mythic, Sliver, AsyncRAT, MeshAgent, and Brute Ratel. In addition, telemetry links part of the servers to the activity of partners or groups working with ransomware. Intersections with Cl0p, ALPHV, BlackCat, Black Basta, Ryuk, and MalSmoke operations are mentioned in the analyzed clusters, while the confidence level for individual connections is assessed as low due to a lack of simultaneous technical features.
Despite the expansion of the fingerprint set and the emergence of a new server shuffling scheme, ShadowSyndicate's hosting preferences, according to the authors, remain fairly stable. This makes infrastructure patterns more predictable for correlation and early detection. At the same time, the final role of ShadowSyndicate in the criminal chain has not yet been confirmed, and Group-IB is considering working as a primary access broker or as a provider of "impenetrable" hosting for other market participants.

Behind the scenes of many extortion attacks, there remains an invisible but important part of the cybercrime ecosystem — the infrastructure that helps attackers quickly deploy tools and change platforms. The new analysis of Group-IB shows that the ShadowSyndicate activity cluster continues to evolve, maintaining recognizable technical habits and at the same time making it more difficult to mask connections between servers.
ShadowSyndicate combines different campaigns by intersecting infrastructure. The authors of the report note that cluster members actively use OpenSSH and usually rely on repeated SSH fingerprints, which allow connecting a large number of servers. Earlier, Group-IB described one of these prints, and the Intrinsec team later reported another similar one. In the new work, Group-IB confirms two additional SSH fingerprints, which also repeatedly occurred on different nodes and formed separate server clusters.
A key new observation was the tactic of reusing the already used infrastructure with the transfer of servers between "SSH clusters". Outwardly, this may look like a normal change of ownership, but operational security errors led to an intersection of keys and helped to prove the connection between the "old" and "new" use of resources. According to Group-IB estimates, at least two dozen servers were used as control nodes for various frameworks.
The detected infrastructure contained traces of toolkits that are often found in post-initial penetration attacks, including Cobalt Strike, Metasploit, Havoc, Mythic, Sliver, AsyncRAT, MeshAgent, and Brute Ratel. In addition, telemetry links part of the servers to the activity of partners or groups working with ransomware. Intersections with Cl0p, ALPHV, BlackCat, Black Basta, Ryuk, and MalSmoke operations are mentioned in the analyzed clusters, while the confidence level for individual connections is assessed as low due to a lack of simultaneous technical features.
Despite the expansion of the fingerprint set and the emergence of a new server shuffling scheme, ShadowSyndicate's hosting preferences, according to the authors, remain fairly stable. This makes infrastructure patterns more predictable for correlation and early detection. At the same time, the final role of ShadowSyndicate in the criminal chain has not yet been confirmed, and Group-IB is considering working as a primary access broker or as a provider of "impenetrable" hosting for other market participants.