SynAck

S0242

Malware.View on attack.mitre.org

About this malware

SynAck is variant of Trojan ransomware targeting mainly English-speaking users since at least fall 2017.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1007
System Service Discovery

SynAck enumerates all running services.

T1012
Query Registry

SynAck enumerates Registry keys associated with event logs.

T1027
Obfuscated Files or Information

SynAck payloads are obfuscated prior to compilation to inhibit analysis and/or reverse engineering.

T1033
System Owner/User Discovery

SynAck gathers user names from infected hosts.

T1055.013
Process Doppelgänging

SynAck abuses NTFS transactions to launch and conceal malicious processes.

T1057
Process Discovery

SynAck enumerates all running processes.

T1082
System Information Discovery

SynAck gathers computer names, OS version info, and also checks installed keyboard layouts to estimate if it has been launched from a certain list of countries.

T1083
File and Directory Discovery

SynAck checks its directory location in an attempt to avoid launching in a sandbox.

T1106
Native API

SynAck parses the export tables of system DLLs to locate and call various Windows API functions.

T1112
Modify Registry

SynAck can manipulate Registry keys.

T1486
Data Encrypted for Impact

SynAck encrypts the victims machine followed by asking the victim to pay a ransom.

T1497.001
System Checks

SynAck checks its directory location in an attempt to avoid launching in a sandbox.

T1614.001
System Language Discovery

SynAck lists all the keyboard layouts installed on the victim’s system using GetKeyboardLayoutList API and checks against a hardcoded language code list. If a match if found, SynAck sleeps for 300 seconds and then exits without encrypting files.

T1685.005
Clear Windows Event Logs

SynAck clears event logs.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. Kaspersky Lab SynAck May 2018 Open source
    Bettencourt, J. (2018, May 7). Kaspersky Lab finds new variant of SynAck ransomware using sophisticated Doppelgänging technique. Retrieved May 24, 2018.
  2. SecureList SynAck Doppelgänging May 2018 Open source
    Ivanov, A. et al. (2018, May 7). SynAck targeted ransomware uses the Doppelgänging technique. Retrieved May 22, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.