NEWS The disguise of the "so-so" level. Group-IB has found new traces of the largest shadow provider

MOON ADM

Well-known member
Member
Joined
Jan 22, 2026
Messages
101
Reaction score
923
One wrong move, and the scheme began to fall apart at the seams.

1770504335876.png

Behind the scenes of many extortion attacks, there remains an invisible but important part of the cybercrime ecosystem — the infrastructure that helps attackers quickly deploy tools and change platforms. The new analysis of Group-IB shows that the ShadowSyndicate activity cluster continues to evolve, maintaining recognizable technical habits and at the same time making it more difficult to mask connections between servers.

ShadowSyndicate combines different campaigns by intersecting infrastructure. The authors of the report note that cluster members actively use OpenSSH and usually rely on repeated SSH fingerprints, which allow connecting a large number of servers. Earlier, Group-IB described one of these prints, and the Intrinsec team later reported another similar one. In the new work, Group-IB confirms two additional SSH fingerprints, which also repeatedly occurred on different nodes and formed separate server clusters.

A key new observation was the tactic of reusing the already used infrastructure with the transfer of servers between "SSH clusters". Outwardly, this may look like a normal change of ownership, but operational security errors led to an intersection of keys and helped to prove the connection between the "old" and "new" use of resources. According to Group-IB estimates, at least two dozen servers were used as control nodes for various frameworks.

The detected infrastructure contained traces of toolkits that are often found in post-initial penetration attacks, including Cobalt Strike, Metasploit, Havoc, Mythic, Sliver, AsyncRAT, MeshAgent, and Brute Ratel. In addition, telemetry links part of the servers to the activity of partners or groups working with ransomware. Intersections with Cl0p, ALPHV, BlackCat, Black Basta, Ryuk, and MalSmoke operations are mentioned in the analyzed clusters, while the confidence level for individual connections is assessed as low due to a lack of simultaneous technical features.

Despite the expansion of the fingerprint set and the emergence of a new server shuffling scheme, ShadowSyndicate's hosting preferences, according to the authors, remain fairly stable. This makes infrastructure patterns more predictable for correlation and early detection. At the same time, the final role of ShadowSyndicate in the criminal chain has not yet been confirmed, and Group-IB is considering working as a primary access broker or as a provider of "impenetrable" hosting for other market participants.
 

MOONCLUBFORUMS

Well-known member
Member
Joined
Jul 12, 2026
Messages
120
Reaction score
0
Location
ABD
One wrong move, and the scheme began to fall apart at the seams.

View attachment 39

Behind the scenes of many extortion attacks, there remains an invisible but important part of the cybercrime ecosystem — the infrastructure that helps attackers quickly deploy tools and change platforms. The new analysis of Group-IB shows that the ShadowSyndicate activity cluster continues to evolve, maintaining recognizable technical habits and at the same time making it more difficult to mask connections between servers.

ShadowSyndicate combines different campaigns by intersecting infrastructure. The authors of the report note that cluster members actively use OpenSSH and usually rely on repeated SSH fingerprints, which allow connecting a large number of servers. Earlier, Group-IB described one of these prints, and the Intrinsec team later reported another similar one. In the new work, Group-IB confirms two additional SSH fingerprints, which also repeatedly occurred on different nodes and formed separate server clusters.

A key new observation was the tactic of reusing the already used infrastructure with the transfer of servers between "SSH clusters". Outwardly, this may look like a normal change of ownership, but operational security errors led to an intersection of keys and helped to prove the connection between the "old" and "new" use of resources. According to Group-IB estimates, at least two dozen servers were used as control nodes for various frameworks.

The detected infrastructure contained traces of toolkits that are often found in post-initial penetration attacks, including Cobalt Strike, Metasploit, Havoc, Mythic, Sliver, AsyncRAT, MeshAgent, and Brute Ratel. In addition, telemetry links part of the servers to the activity of partners or groups working with ransomware. Intersections with Cl0p, ALPHV, BlackCat, Black Basta, Ryuk, and MalSmoke operations are mentioned in the analyzed clusters, while the confidence level for individual connections is assessed as low due to a lack of simultaneous technical features.

Despite the expansion of the fingerprint set and the emergence of a new server shuffling scheme, ShadowSyndicate's hosting preferences, according to the authors, remain fairly stable. This makes infrastructure patterns more predictable for correlation and early detection. At the same time, the final role of ShadowSyndicate in the criminal chain has not yet been confirmed, and Group-IB is considering working as a primary access broker or as a provider of "impenetrable" hosting for other market participants.
Credit Credit card Credit card counterfeit money Credit card counterfeit money bomb Credit card counterfeit money bomb trigger Credit card, counterfeit money, bomb, hitman, drugs Credit card, counterfeit money, bomb, hitman, drugs, weapon Credit card, counterfeit money, bomb, gunman, drugs, weapon, hacker Credit card, counterfeit money, bomb, gunman, drugs, weapon, hacker, military Credit card, counterfeit money, bomb, gunman, drugs, weapon, hacker, military weapons Credit card, counterfeit money, bomb, gunman, drugs, weapon, hacker, military weapons, spy Credit card, counterfeit money, bomb, gunman, drugs, weapon, hacker, military weapons, spy, intelligence. Credit card, counterfeit money, bomb, hitman, drugs, weapon, hacker, military weapons, spy, intelligence agent Credit card, counterfeit money, bomb, gunman, drugs, weapon, hacker, military weapons, spy, intelligence agents, fake. Credit card, counterfeit money, bomb, gunman, drugs, weapon, hacker, military weapons, spy, intelligence agents, counterfeit money. Credit card, counterfeit money, bomb, gunman, drugs, weapon, hacker, military weapons, spy, intelligence agents, counterfeit money, flash Credit card, counterfeit money, bomb, gunman, drugs, weapon, hacker, military weapons, spy, intelligence agents, counterfeit money, flash USDT Credit card, counterfeit money, bomb, gunman, drugs, weapon, hacker, military weapons, spy, intelligence agents, counterfeit money, flash USDT, crypto software. Credit cards, counterfeit money, bombs, gunmen, drugs, weapons, hackers, military weapons, spies, intelligence agents, counterfeit money, flash USDT, crypto software, bank accounts, money. Credit card, counterfeit money, bomb, gunman, drugs, weapon, hacker, military weapons, spy, intelligence agents, counterfeit money, flash USDT, crypto software, depositing money into bank accounts Credit card, counterfeit money, bomb, gunman, drugs, weapon, hacker, military weapons, spy, intelligence agents, counterfeit money, flash USDT, crypto software, depositing money into bank accounts Mercenary mercenary hitman mercenary hitman assassin mercenary hitman assassin magic books mercenary hitman assassin magic books credit card mercenary hitman assassin magic books credit card mercenary, hitman, assassin, magic books, credit card, card clone mercenary hitman assassin spell books credit card card clone card wars mercenary hitman assassin spell books credit card card clone card wars

Session

050bbbee83794febed3c001a153cf99f2474b71f0952ba019fc62a1b206401a819
 
5,643Threads
75,606Messages
5,828Members
Whoami88Latest member
Top Bottom