A new and improved version of the SynAck ransomware has been detected in recent days, and various security researchers report that the software now uses the process Doppelgänging technique.

Doppelgänging is a technique that uses Windows NTFS to create and hide malicious code in an attempt to avoid detection by antiransomware software. The technique is relatively new, first demonstrated at a security conference in December of last year, but some ransomware have been using it for a long time.
SynAck was extremely active in August and September 2017, when it was in its early stages of development and was a relatively minor threat. However, in a report released a few days ago, Kaspersky describe a very well-developed ransomware that uses a fairly high-quality encryption routine, Doppelganging, and a general design that makes reverse engineering difficult.
The original version of SynAck spread when some users accessed servers via open RDP connections. The new version, on the other hand, does not appear to be spreading via any malspam, so it is very likely that the crooks are still using the same process.
Below you can see some of the changes:
- Mixed encryption ECIES-XOR-HMAC-SHA1
- The extension of encrypted files includes 10 random characters.
- Terminates selected processes so that running applications do not interfere with the encryption operation.
- It cleans event logs to prevent any forensic analysis.
- Ransomware will not execute if its .exe file is not in a whitelisted path.
- Most of the users it infects are located in the US, Kuwait, Germany, and Iran.
