Actor Profile

🏹 ShadowByt3$ — Ransomware

ShadowByt3$ is a ransomware-as-a-service group first observed in October 2025, using multi-method extortion and communicating via Telegram and Tox, with a very small confirmed victim list suggesting it remains in early-stage operation.

Classification

Ransomware

Leak-site victims

12
Ransomware.live

Associated IoCs

0
local intel

MITRE techniques

ATT&CK

Tracked

Yes
Ransomware.live

🔥 Leak-Site Victims (12)

VictimCountryPublishedDomain
TINYpulse NINTENDO BREACH (nintendo.com) JP 2026-06-16T06:50:21.954593+00:00 nintendo.com
Nintendo Company (Nintendo.com) JP 2026-06-12T17:50:18.874752+00:00 Nintendo.com
Lead Company (Leadership Boulevard) 2026-06-03T00:20:16.635974+00:00
Cropwise (Syngenta Group) CH 2026-06-02T04:20:12.877865+00:00
Hotelogix Company (Hotelogix.com) IN 2026-05-21T06:22:11.225742+00:00 Hotelogix.com
Stride Learning US 2026-05-14T16:47:59.675677+00:00 stridelearning.com
Amplify Technology GB 2026-05-14T16:47:47.254724+00:00 amplifytechnology.co.uk
University Of Georgia US 2026-05-14T16:47:31.750340+00:00 uga.edu
Hotelogix SG 2026-05-14T16:47:19.110857+00:00 hotelogix.com
PowerCampus IN 2026-05-14T19:49:40.855479+00:00 powercampus.in
StarBucks Company (StarBucks.com US 2026-05-21T05:52:10.947443+00:00 Starbucks.com
UMSA 2026-02-25T12:54:56.965666+00:00

Source: Ransomware.live leak-site monitoring (cached, offline-safe).

📁 Case Management

+ New case from this

🏹 Add to case

Attach ShadowByt3$ (Actor / APT) and pull all linked entities:

🧭 Intelligence disciplines

CYBINT →OSINT →HUMINT →GEOINT →
Live group profile & victims via Ransomware.live; ATT&CK technique hints are a static reference for well-known groups. All network calls cached & offline-safe.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php