Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Shadowbyt3$

| RaaS

ShadowByt3$ is a ransomware-as-a-service group first observed in October 2025, using multi-method extortion and communicating via Telegram and Tox, with a very small confirmed victim list suggesting it remains in early-stage operation.

Victims
1
 
First Discovered
2026-02-25
victim
Last Discovered
2026-02-25
victim
Inactive Since
77
days
Avg Delay
8
days
Infostealer
N/A
victims with domain
Countries
0
hit
View Victims on World Map View Group Statistics
Attack Velocity — Last 12 months

Known Locations (2)
Favicon Title Type Available Last Visit Server Info FQDN
favicon Leaks No 2026-05-13T20:11:31 mfbbt65kir2drc7tuoukwibikgvxquauscnzgbeltkmidjtgqlzm2qad.onion
favicon ShadowByt3$ No 2026-04-28T07:28:57 shadowbyt3s.8bit.ca

Target
Top 5 Activity Sectors
Top 5 Countries

Heatmap

YARA Rules (1)

Victims (1)
Logo
Discovered: 2026-02-25 (2mo ago)  ·  Attack est.: 2026-02-17
File: UMSA_LEAK.7z…