{"id":339,"date":"2018-05-08T12:10:13","date_gmt":"2018-05-08T12:10:13","guid":{"rendered":"http:\/\/c09ad9e2-b185-4ed9-a831-5ab3518eacea"},"modified":"2018-05-08T12:10:13","modified_gmt":"2018-05-08T12:10:13","slug":"synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique\/","title":{"rendered":"SynAck ransomware circumvents antivirus software through Doppelg\u00e4nging technique"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/zdnet4.cbsistatic.com\/hub\/i\/r\/2018\/05\/08\/84c08576-9892-4a89-bfe0-d4c7f20437d5\/thumbnail\/770x578\/d0357a3d191667305c47f8a23f16e1a4\/hackingx6rocco.jpg\" class=\"ff-og-image-inserted\"\/><\/div>\n<p>Researchers have discovered what is believed to be the first case of ransomware using a sophisticated technique called Doppelg\u00e4nging to avoid detection by antivirus solutions.<\/p>\n<div class=\"relatedContent alignRight\">\n<h3 class=\"heading\"><span class=\"int\">More security news<\/span><\/h3>\n<\/div>\n<p>On Monday, security experts from Kaspersky Lab <a href=\"https:\/\/securelist.com\/synack-targeted-ransomware-uses-the-doppelganging-technique\/85431\/\">said in a security notice<\/a> that a variant of the SynAck ransomware has been spotted in the wild using this sophisticated circumvention technique.<\/p>\n<p>SynAck is <a href=\"https:\/\/www.scmagazine.com\/synack-ransomware-activity-on-the-rise\/article\/686828\/\">nothing new<\/a>. The ransomware was discovered in 2017 and differs from standard ransomware families in several ways. While SynAck employs the standard recipe of infection, encryption, and a blackmail notice demanding money in return for a decryption key, the ransomware does not use a payment portal.<\/p>\n<p>Instead, SynAck operators demand that victims arrange payment, usually in Bitcoin (BTC), through email or a BitMessage ID. Ransom demands can be as high as $3,000.<\/p>\n<p>While this malware may have previously been nothing special, the emergence of a variant which utilizes the Doppelg\u00e4nging technique has forced researchers to take notice.<\/p>\n<p>Process Doppelg\u00e4nging <a href=\"https:\/\/www.zdnet.com\/article\/dancing-around-security-products-to-execute-code-on-windows\/\">was first revealed by enSilo researchers<\/a> at Black Hat Europe in December last year.<\/p>\n<p>The attack technique targets the Microsoft Windows operating system and is designed to circumvent traditional security software and antivirus solutions by exploiting how they interact with memory processes.<\/p>\n<section class=\"sharethrough-top\" data-component=\"medusaContentRecommendation\" data-medusa-content-recommendation-options=\"{&quot;promo&quot;:&quot;promo_ZD_recommendation_sharethrough_top_in_article_desktop&quot;,&quot;spot&quot;:&quot;dfp-in-article&quot;}\">\n<\/section>\n<p>Process Doppelg\u00e4nging masks crafted executables and changes executable files by overwriting legitimate files in the context of transactional NTFS. A section of these transactions is overwritten with malicious code that points to a crafted executable, which is then loaded and results in the creation of a process based on the modified executable.<\/p>\n<p>This is known as process hollowing, the creation of a process purely in order to run malicious executables.<\/p>\n<p>While many antivirus products are able to detect and thwart such attack techniques, Doppelg\u00e4nging then rolls back transactions into legitimate states, and so no trace of the attack is left behind &#8212; which prevents antivirus solutions from detecting such activity at all.<\/p>\n<p>Arbitrary code is then able to run in the context of a legitimate process. According to enSilo, Doppelg\u00e4nging is a fileless injectable attack, and it cannot be patched as it &#8220;exploits fundamental features and the core design of the process loading mechanism in Windows.&#8221;<\/p>\n<p>Kaspersky Labs researchers say that alongside the use of Doppelg\u00e4nging, SynAck will also attempt to prevent programs related to virtual machines, office software, backup systems, and more from operating.<\/p>\n<p>&#8220;It might be doing this to grant itself access to valuable files that could have been otherwise used by the running processes,&#8221; the researchers say.<\/p>\n<p>In addition, the malware has been thoroughly obfuscated prior to compilation, as well as encrypted, which makes reverse engineering a strenuous task.<\/p>\n<p><strong>See also: <a href=\"https:\/\/www.zdnet.com\/article\/this-malware-checks-your-system-temperature-to-sidestep-sandboxing\/\">This malware checks your system temperature to sidestep sandboxing<\/a><\/strong><\/p>\n<p>Attacks using the new SynAck variant have been recorded in the United States, Kuwait, Germany, and Iran.<\/p>\n<p>Kaspersky believes that the ransomware is targeted, especially as the malware will check the status of an infected machine against a hardcoded list of countries and languages.<\/p>\n<p>If a victim is located in a country outside of an approved list, then the encryption of files will not take place and the malware simply exits.<\/p>\n<p>&#8220;The ability of the Process Doppelg\u00e4nging technique to sneak malware past the latest security measures represents a significant threat; one that has, not surprisingly, quickly been seized upon by attackers,&#8221; said Anton Ivanov, lead malware analyst at Kaspersky Lab. &#8220;Our research shows how the relatively low profile, targeted ransomware SynAck used the technique to upgrade its stealth and infection capability. Fortunately, the detection logic for this ransomware was implemented before it appeared in the wild.&#8221;<\/p>\n<h3>Previous and related coverage<\/h3>\n<p>Read More <a href=\"https:\/\/www.zdnet.com\/article\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique\/#ftag=RSSbaffb68\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This is the first kind of ransomware believed to use the sophisticated antivirus bypass method.<br \/>\nRead More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":340,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[62],"tags":[],"class_list":["post-339","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-zdnet-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>SynAck ransomware circumvents antivirus software through Doppelg\u00e4nging technique 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SynAck ransomware circumvents antivirus software through Doppelg\u00e4nging technique 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2018-05-08T12:10:13+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"770\" \/>\n\t<meta property=\"og:image:height\" content=\"578\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"SynAck ransomware circumvents antivirus software through Doppelg\u00e4nging technique\",\"datePublished\":\"2018-05-08T12:10:13+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique\\\/\"},\"wordCount\":612,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/05\\\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique.jpg\",\"articleSection\":[\"ZDNet | Security\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique\\\/\",\"name\":\"SynAck ransomware circumvents antivirus software through Doppelg\u00e4nging technique 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/05\\\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique.jpg\",\"datePublished\":\"2018-05-08T12:10:13+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/05\\\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/05\\\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique.jpg\",\"width\":770,\"height\":578},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"SynAck ransomware circumvents antivirus software through Doppelg\u00e4nging technique\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"SynAck ransomware circumvents antivirus software through Doppelg\u00e4nging technique 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique\/","og_locale":"en_US","og_type":"article","og_title":"SynAck ransomware circumvents antivirus software through Doppelg\u00e4nging technique 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2018-05-08T12:10:13+00:00","og_image":[{"width":770,"height":578,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"SynAck ransomware circumvents antivirus software through Doppelg\u00e4nging technique","datePublished":"2018-05-08T12:10:13+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique\/"},"wordCount":612,"commentCount":0,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique.jpg","articleSection":["ZDNet | Security"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.threatshub.org\/blog\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique\/","url":"https:\/\/www.threatshub.org\/blog\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique\/","name":"SynAck ransomware circumvents antivirus software through Doppelg\u00e4nging technique 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique.jpg","datePublished":"2018-05-08T12:10:13+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique.jpg","width":770,"height":578},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/synack-ransomware-circumvents-antivirus-software-through-doppelganging-technique\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"SynAck ransomware circumvents antivirus software through Doppelg\u00e4nging technique"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/339","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=339"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/339\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/340"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=339"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=339"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=339"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}