Syteca (formerly Ekran) is a legitimate employee monitoring application that was observed being abused during a May 2025 Fog ransomware intrusion against a financial institution in Asia. In the reported attack, operators used the open-source proxy tool Stowaway to deploy Syteca onto victim systems. The software supports screen recording, onscreen activity capture, and keystroke monitoring, and reporting assessed it was likely used for information theft or spying rather than as ransomware itself. The broader intrusion involved a two-week dwell time before ransomware deployment and included other tools such as GC2, Adaptix, PsExec, SMBExec, FreeFileSync, MegaSync, 7-zip, and Impacket. Symantec noted the use of Syteca was highly unusual in a ransomware attack chain and, together with post-ransomware persistence, suggested possible espionage objectives in addition to financial extortion. Attackers later attempted to remove Syteca and related evidence using taskkill, PsExec, and SMBExec. High-confidence context directly associates Syteca with the Fog ransomware operators in this incident; no standalone malicious infection vector for Syteca was described because it is legitimate software repurposed by the attackers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Legitimate employee monitoring software referenced as being abused by Fog ransomware operators for monitoring/persistence in intrusions.
Syteca (formerly Ekran) is legitimate employee monitoring software with keylogging and screen capture capabilities. In this context, it was abused by attackers for surveillance and possible information theft during a ransomware attack.
Legitimate employee monitoring software repurposed by attackers for information stealing, keylogging, and screen capture during intrusions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.