← Back to Pulse Feed
PULSE DETAIL
ShadowByt3$ is a ransomware group that emerged in late October 2025, actively recruiting affiliates across dark web forums. While they seek to present themselves as a sophisticated ransomware operation, a detailed analysis reveals significant shortcomings in their technical execution. Their primary ransomware variant employs AES-256-GCM for file data encryption and uses RSA-2048 for key wrapping, while an alternative Windows variant utilizes the ECIES scheme with ChaCha20. Notably, their malware incorporates a polymorphic builder that generates unique hashes for every deployment, yielding low detection rates on VirusTotal-0 out of 65 for the Linux version and 4 out of 72 for Windows.
MITRE ATT&CK & Malware Families
Indicators of Compromise (8)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| BitcoinAddress | bc1qh4ynm9fj69apv2t0kv7xu6jmtqptna4q8v5rgl | — | 2026-04-26 | |
| FileHash-SHA256 | 3a253393fab8606296654cff93e033b9912324c21e802d175b0329fa865827bc | — | 2026-04-26 | |
| FileHash-SHA256 | ccae7ab0a069b628aed34ed696704f5b4d1df6843c5e58b5dec821084c275d68 | — | 2026-04-26 | |
| URL | http://mfbbt65kir2drc7tuoukwibikgvxquauscnzgbeltkmidjtgqlzm2qad.onion/leaks.php | — | 2026-04-26 | |
| domain | mfbbt65kir2drc7tuoukwibikgvxquauscnzgbeltkmidjtgqlzm2qad.onion | — | 2026-04-26 | |
| domain | sdwbytqeb664krp2wz2qs3lxxah2rhneuotot5hy7g4jpn2pindigcad.onion | — | 2026-04-26 | |
| shadowbyt3s@proton.me | — | 2026-04-26 | ||
| hostname | shadowsblog.cloud-ip.cc | — | 2026-04-26 |