PULSE NAME
ShadowByt3$ Ransomware Group
WHITE Shadowbyt3 PetrP.73 2026-04-26 Modified: 2026-04-26
8
IOCs
LOW VOLUME
ShadowByt3$ is a ransomware group that emerged in late October 2025, actively recruiting affiliates across dark web forums. While they seek to present themselves as a sophisticated ransomware operation, a detailed analysis reveals significant shortcomings in their technical execution. Their primary ransomware variant employs AES-256-GCM for file data encryption and uses RSA-2048 for key wrapping, while an alternative Windows variant utilizes the ECIES scheme with ChaCha20. Notably, their malware incorporates a polymorphic builder that generates unique hashes for every deployment, yielding low detection rates on VirusTotal-0 out of 65 for the Linux version and 4 out of 72 for Windows.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (8)
All BitcoinAddress FileHash-SHA256 URL domain email hostname
TYPEINDICATORDESCRIPTIONCREATED
BitcoinAddress bc1qh4ynm9fj69apv2t0kv7xu6jmtqptna4q8v5rgl 2026-04-26
FileHash-SHA256 3a253393fab8606296654cff93e033b9912324c21e802d175b0329fa865827bc 2026-04-26
FileHash-SHA256 ccae7ab0a069b628aed34ed696704f5b4d1df6843c5e58b5dec821084c275d68 2026-04-26
URL http://mfbbt65kir2drc7tuoukwibikgvxquauscnzgbeltkmidjtgqlzm2qad.onion/leaks.php 2026-04-26
domain mfbbt65kir2drc7tuoukwibikgvxquauscnzgbeltkmidjtgqlzm2qad.onion 2026-04-26
domain sdwbytqeb664krp2wz2qs3lxxah2rhneuotot5hy7g4jpn2pindigcad.onion 2026-04-26
email shadowbyt3s@proton.me 2026-04-26
hostname shadowsblog.cloud-ip.cc 2026-04-26