• About WordPress
    • WordPress.org
    • Documentation
    • Learn WordPress
    • Support
    • Feedback
Skip to content
May 26, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Malware
  • The first ransomware SynAck use Process Doppelgänging code injection technology
  • Malware

The first ransomware SynAck use Process Doppelgänging code injection technology

Ddos May 9, 2018 3 minutes read

At the Black Hat 2017 Security Conference held in London, the UK on December 7, 2017, two researchers from network security company enSilo, Tal Liberman and Eugene Kogan, described to us a new type of code injection technology. They will It is named “Process Doppelgänging”.

Process Doppelgänging is described as being able to work on almost all Windows operating systems, from Windows Vista to the latest Windows. In addition, because the use of Process Doppelgänging’s malicious software code will not be saved to the local hard disk (known as “fileless attack“), this makes the vast majority of popular security products and forensic tools currently on the market cannot detect this malicious software.

Researchers stated that they have tested Process Doppelgänging injection technology for various security products, including Windows Defender, Kaspersky Labs, ESET NOD32, Symantec, Trend Micro, Avast, McAfee, AVG, Panda, and even some advanced forensics tools (such as Internal memory card tool Volatility). The result is shocking, and none of these security products and forensics tools can detect malware that uses the technology.

Kaspersky Lab released a report on Monday that they discovered the first ransomware using this code injection technology, SynAck, last month. It should be noted that SynAck is not a new ransomware that has only recently emerged. The earliest time it was discovered dates back to September 2017, but recently discovered samples are using Process Doppelgänging technology.

There is no doubt that SynAck’s use of Process Doppelgänging technology is aimed at trying to bypass the detection of security products. This technology uses the NTFS mechanism of the Windows operating system to start malicious processes from transaction files so that these processes appear to be legitimate processes.

In general, to complicate the work of a malware analyst, malware developers often use custom PE packages to protect the original code of malware executable files. However, SynAck’s developers did not seem to do so, and they did not package the ransomware executable. However, they added a lot of obfuscated code to SynAck’s source code, which made it extremely difficult to analyze SynAck.

Before encrypting a file, SynAck retrieves all running processes and services and checks the hash of its name against a list of two hard-coded hash values (hundreds of combinations). If a match is found, it will try to terminate these processes or stop the service.

SynAck attempts to terminate programs related to virtual machines, office applications, script interpreters, database applications, backup systems, and game applications. Researchers believe that SynAc’s purpose is to grant itself access to valuable files used by these processes.

Like other ransomware, SynAck also collects basic information about the infected host, such as computer and usernames, operating system version information, etc., and then encrypts the target file using a randomly generated 256-bit AES key. After the file is encrypted, it will be appended with a random production extension.

In addition, SynAck also clears the system-stored event log and can add custom text to the Windows login screen by modifying the LegalNoticeCaption and LegalNoticeText keys in the registry. Therefore, Windows will display messages from cybercriminals before users log in to their accounts.

 

Kaspersky concluded that they are currently monitoring several SynAck ransomware attacks in the United States, Kuwait, Germany, and Iran. This convinced them that the ransomware was specifically tailored to specific goals.

Rate this post

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram

Related posts:

  1. Updated ShadowPad Malware Facilitates Ransomware Deployment in Global Attacks
  2. PolarEdge Botnet: 2,000+ IoT Devices Infected
  3. XMRig Cryptojacking Surges: New Campaign Uses LOLBAS, Steals Monero Undetected
  4. Wonderland Unleashed: New Android “Dropper” Malware Hijacks Telegram to Drain Bank Accounts
  5. “Contagious Interview” Goes macOS: North Korean Hackers Deploy Stealthy “DriverFixer” Stealer
Tags: ransomware SynAck

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🔴 Live Critical Threats

  • CVE-2026-42773CVSS 9.3
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
  • CVE-2026-42774CVSS 9.3
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
  • CVE-2026-9478CVSS 9.8
    A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the...
  • CVE-2026-9477CVSS 9.8
    A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue...
  • CVE-2026-9476CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the...
  • CVE-2026-9475CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function...
  • CVE-2026-9458CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is...
  • CVE-2026-9457CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affected element is...
  • CVE-2026-9456CVSS 9.8
    A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function...
  • CVE-2026-9455CVSS 9.8
    A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
  • Exploited in the Wild: Maximum CVSS 10 SD-WAN Flaw (CVE-2026-20182) Grants Admin Control
  • Exploited in the Wild: Critical 9.8 CVSS RCE Hits Canon GUARDIANWALL MailSuite
  • Exploit Code Released: Public PoC Dumps for Windows BitLocker Bypass and SYSTEM Elevation Zero-Days
  • Exploited in the Wild: “Dirty Frag” Linux Vulnerability Grants Instant Root Access
  • Under Active Attack: Ivanti EPMM Zero-Day Exploited in the Wild via Harvested Admin Credentials
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    Copyright Daily CyberSecurity © All rights reserved.