A sophisticated malware family has emerged onto the cyberthreat scene that might foreshadow ransomware attacks that are more successful than usual.
Marcus Hutchins and his colleagues at Expel that discovered it named the malware "SynkLoader," since it throws so many ideas ("everything but the kitchen sink") at trying to sneakily dig into corporate systems. It uses some conventional strategies — like executing code in-memory, running a scheduled task, etc. — but layers on a few interesting, novel tactics that make social engineering particularly compelling, and malware analysis especially frustrating.
The program is new, and how its creators intend to use it remains a mystery. But evidence in the code suggests that it might be the baby of a ransomware group or initial access broker (IAB), used to set the stage for follow-on ransomware.
Intro to the SynkLoader Malware
SynkLoader's compilation metadata suggests that it was probably first deployed on July 28. Researchers first discovered it in a client's network on Aug. 18, Hutchins tells Dark Reading.