ShadowByt3$
ShadowByt3$ is a ransomware-as-a-service group first observed in October 2025, using multi-method extortion and communicating via Telegram and Tox, with a very small confirmed victim list suggesting it remains in early-stage operation.
ShadowByt3$ is a ransomware-as-a-service group employing multi-method extortion primarily in Japan and Switzerland.
ShadowByt3$ is a ransomware-as-a-service group that was first observed in October 2025. It primarily targets the technology, professional services, and agriculture and food production sectors in Japan and Switzerland. The group employs multi-method extortion TTPs, communicates via Telegram and Tox, and its very small confirmed victim list suggests it is still in an early operational stage. Defenders should focus on anomalous network behaviors, potential data exfiltration channels used for multi-method extortion, and monitor for C2 communication over Telegram and Tox.
ShadowByt3$ is a ransomware-as-a-service group first observed in October 2025, using multi-method extortion and communicating via Telegram and Tox, with a very small confirmed victim list suggesting it remains in early-stage operation.
ShadowByt3$ primarily targets the technology, professional services, and agriculture and food production sectors in Japan and Switzerland.
ShadowByt3$ employs multi-method extortion TTPs.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.