ShadowSyndicate

THREAT ACTOR PROFILE

ShadowSyndicate

ShadowSyndicate

ShadowSyndicate

ShadowSyndicate is a financially motivated threat actor active since at least July 2022 that works with multiple ransomware-as-a-service programs rather than running its own brand. It has deployed RansomHub, Clop, Royal, Quantum and others, and researchers have tracked it through reused SSH fingerprints across large clusters of command-and-control servers.

Not attributed

Ransomware affiliate / Access

First seen

2022

Latest IOC

-

IP indicators

Hosts

SHA256 hashes

Posts

NAMES AND ALIASES

ShadowSyndicate and Infra Storm

ShadowSyndicate is tracked under its own name and one infrastructure-based handle. It maps to one entry among the ransomware affiliates we track, and its multi-RaaS model overlaps with access-brokering crews feeding programs like RansomHub.

-

-

-

GROUP PROFILE

One affiliate, many ransomware brands

ShadowSyndicate is a cross-program affiliate. Instead of a single locker, it partners with multiple RaaS operations and deploys whichever payload fits, which makes infrastructure tracking more useful than payload-based attribution.

Our record ties it to financially motivated ransomware activity across several brands. Darktrace linked it to RansomHub intrusions in late 2024, and Group-IB documented new infrastructure with additional SSH fingerprints and heavy key reuse.

The group favors stable hosting ASNs and rotates SSH keys across reused servers to evade tracking, running numerous C2 servers that support varied post-exploitation frameworks.

Facts:

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Victims reported in our records and posts:

-

-

-

ATTACK LIFECYCLE

Access into multi-brand ransomware deployment

The stages below come from ShadowSyndicate activity in posts we track on our IOC Hunter feed.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

MALWARE AND TOOLING

CVES EXPLOITED

Aiohttp directory traversal

CVE-2026-21509

A Microsoft Office security bypass used to open the fileless chain in Operation Neusploit, and again in the PixyNetLoader intrusion chain. Both campaigns paired the exploit with spear-phishing from compromised accounts rather than mass exploitation.

ShadowSyndicate

IOCS FROM HUNT.IO PLATFORM

Latest IOCs

We currently track - IP indicators, - hosts, and - SHA256 hashes for Akira across - intelligence posts, with the most recent indicator dated -. The sample below is limited to indicators from the latest posts. It is not the full set.

ShadowSyndicate

Hosting Company

IPs

Date

Hosting Company

IPs

Date

144.126.202.227

LameHug exfil

06-17

Showing a sample of recent indicators

Get the complete

ShadowSyndicate

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

ShadowSyndicate

IOC set, full IP, host and hash history.

NOTABLE CAMPAIGNS

Server transition and RansomHub deployment

Recent reporting tracks the group's infrastructure and payloads.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

Showing a sample of recent indicators

Get the complete

ShadowSyndicate

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

ShadowSyndicate

IOC set, full IP, host and hash history.