SynAck is a Windows ransomware family and associated criminal operation first observed in 2017. It encrypts victim files and systems and then demands payment for decryption. The malware is notable for early adoption of process doppelgänging as an evasion technique, making it one of the first ransomware strains publicly documented using that method to bypass security controls.
SynAck performs substantial host discovery before or during encryption. Documented behaviors include enumerating running processes and services, collecting the current username, and querying or modifying Windows Registry data, including event log-related keys. It also clears event logs, indicating an effort to reduce forensic visibility and hinder incident response. The malware dynamically resolves Windows API functions by parsing export tables of system DLLs, a technique consistent with defense evasion and reduced static detectability.
A characteristic targeting control in SynAck is its language and keyboard-layout filtering. It enumerates installed keyboard layouts through Windows APIs and compares them against a hardcoded exclusion list. If a match is found, the malware delays and exits without encrypting files, reflecting geofencing behavior commonly used to avoid infecting systems in selected regions.
SynAck has been associated with a ransomware group that later rebranded as El_Cometa. During that transition, the operators released master decryption keys covering victims infected from 2017 into early 2021, effectively ending the older SynAck operation. The group reportedly moved from a limited partner model toward a broader ransomware-as-a-service structure under the El_Cometa name.
SynAck targeted Windows environments and fits the broader pattern of financially motivated ransomware intrusions that combine host reconnaissance, anti-forensics, regional exclusion logic, and encryption-based extortion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
BitPaymer has used dynamic API resolution to avoid identifiable strings within the binary, including RegEnumKeyW.
“APT28 has cleared event logs, including by using the commands wevtutil cl System and wevtutil cl Security …” / “APT38 clears Window Event logs and Sysmon logs …” / “BlackCat can clear Windows event logs using wevtutil.exe …” / “NotPetya uses wevtutil to clear the Windows event logs …”
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
Examples include: “Bazar … check if the Russian language is installed … and terminate if it is found.”; “DropBook … checked for the presence of Arabic language …”; “Maze … checked the language … GetUserDefaultUILanguage”; “SynAck … checks installed keyboard layouts to estimate … countries.”
Examples include 'Bazar can also check if the Russian language is installed,' 'DropBook has checked for the presence of Arabic language,' 'Maze has checked the language of the infected system,' and 'SynAck ... checks installed keyboard layouts to estimate if it has been launched from a certain list of countries.'
34 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware that gathers usernames from infected hosts.
Software changes: ... SynAck
Gathers usernames from infected hosts.
Ransomware that parses DLL export tables to resolve and call Windows APIs.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.