ShadowByt3$ — Ransomware Profile
ShadowByt3$ is a ransomware-as-a-service group first observed in October 2025, using multi-method extortion and communicating via Telegram and Tox, with a very small confirmed victim list suggesting it remains in early-stage operation.Also tracked as
ShadowsBlog, ShadowBytes, ShadowByt3$ 2.0
IntelFusions coverage (1)
- Abbott probes two breaches as extortion gangs claim patient data theft 2026-07-20 · Cyber Incidents
Recent claimed victims
- HandyTrac (Greystar Litchfield Park, AZ) 2026-09-15
- John Engel Team 2026-09-10
- Ben Leeds Properties 2026-09-07
- BayView Real Estate 2026-08-29
- Bayview Real Estate WARNING 2026-08-28
- Knottingham Trent University 2026-08-25
- Sinar Mas Agribusiness and Food Golden Agri-Resources) 2026-08-25
- Nintendo Corporation 2026-08-25
- A-Plus Software Limited 2026-08-25
- TINYpulse NINTENDO BREACH (nintendo.com) 2026-06-16
- TINYpulse NINTENDO BREACH 2026-06-16
- Nintendo Company (Nintendo.com) 2026-06-12
- Nintendo Company 2026-06-12
- Lead Company (Leadership Boulevard) 2026-06-03
- Cropwise (Syngenta Group) 2026-06-02
- StarBucks Company (StarBucks.com 2026-05-21
- Hotelogix Company 2026-05-21
- StarBucks Company 2026-05-21
- Hotelogix Company (Hotelogix.com) 2026-05-21
- University Of Georgia 2026-05-14
- PowerCampus 2026-05-14
- Stride Learning 2026-05-14
- Amplify Technology 2026-05-14
- Hotelogix 2026-05-14
Vendor research
- Ransomware Tracker: ShadowByt3$ Ransomware WatchGuard Technologies