Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

Shadowbyt3$

| Active | RaaS

ShadowByt3$ is a ransomware-as-a-service group first observed in October 2025, using multi-method extortion and communicating via Telegram and Tox, with a very small confirmed victim list suggesting it remains in early-stage operation.

Victims
17
 
First Victim
2026-02-17
(est. attack date)
Discovery Date
2026-02-25
 
Last Seen
2026-08-29
 
Inactive Since
1
day
Avg Delay
29
days
Infostealer
64.3%
victims with domain
Countries
7
hit
Uptime
33.2% avg (30d)
View Victims on World Map View Group Statistics
Attack Velocity — Last 12 months (based on attack estimated date if available)
5 victims this month
Exclusive interview with the ransomware group ShadowByt3$ from the CyberSecurityIL Telegram Channel — ransomware-interviews.base44.app

Known Locations (6)
Favicon Title Type Available Last Visit Server Info FQDN Status
favicon Leaks No 2026-08-22T08:41:08 mfbbt65kir2drc7tuoukwibikgvxquauscnzgbeltkmidjtgqlzm2qad.onion
favicon ShadowByt3$ No 2026-08-22T08:40:42 shadowbyt3s.8bit.ca
favicon SB Group No 2026-08-22T08:41:21 52rtvdymcqvebbamd3la3wtu3ofrcuzuzja3vrsu6wiyrq223osptzqd.onion
favicon SB Data Leak Site No 2026-08-22T08:40:59 shdwbt3ja2ptjt6poluegas44i35727lgmoqqquoww642x3zyocyhuqd.onion
favicon No 2026-08-30T09:46:00 sdwbytqeb664krp2wz2qs3lxxah2rhneuotot5hy7g4jpn2pindigcad.onion
favicon [SB] Leaks Yes 2026-08-30T09:46:23 NGINX nginx sdwbyttda4uzwdffbt4m7niuodiwhcgmkyxqg5nly2bjxqa6xtbe3fyd.onion

Target
Top 5 Activity Sectors
  • Education 5
  • Technology 4
  • Hospitality 3
  • Retail & E-Commerce 2
  • Agriculture and Food Production 2
Top 5 Countries
  • US flag United States 5
  • GB flag United Kingdom 3
  • JP flag Japan 2
  • IN flag India 2
  • ID flag Indonesia 1

Heatmap

YARA Rules (1)

Victims (17)
Logo
Discovered: 2026-08-29 (Yesterday)
Guess your too busy focusing on your clients then changing password and protecting your clients. We …
Logo
Discovered: 2026-08-28 (2d ago)
Check your emails or we will leak the data we are not bluffing we stole 216.6 MB. compromised email…
Logo
Discovered: 2026-08-25 (4d ago)
We Breached This company a few months ago. we stole 375.66MB. mirror 1: https://anonfilesnew.com/[RE…
Logo
Discovered: 2026-08-25 (4d ago)
We Breached A-plus through a sql injection vulnerability and downloaded everything in there backend.…
Logo
Discovered: 2026-08-25 (4d ago)
We breached Knottingham trent University on August 19th 2026 by gaining access through webapps.ntu.a…
Logo
Discovered: 2026-06-16 (2mo ago)
This will be quick. You don't even want to read the private messages as some will be embarrasing. So…
Logo
Discovered: 2026-06-12 (2mo ago)
proof: https://mega.nz/folder/3kBzQKgR#rIhDePsPMeFpfEGTPopDVQ We are ShadowByt3$ a extortion as a se…
Logo
Discovered: 2026-06-03 (2mo ago)
Company Site: leadschool.in size: 765.9MB This is will be quick. The following schools are affected:…
Logo
Discovered: 2026-06-02 (2mo ago)
We have breached you and gained access to the following portals: https://operations.cropwise.com/d/u…
Logo
Discovered: 2026-05-21 (3mo ago)
Should've not messed with us Hotelogix. We gave you guys numerous times to reach back and proceed wi…
Logo
Discovered: 2026-05-21 (3mo ago)  ·  Attack est.: 2026-04-01
StarBucks Failed to reach out to us and didn't pay even $500,000 when we know they can afford it. It…
Logo
Discovered: 2026-05-14 (3mo ago)
Cloud-based school management and collaboration platform targeting educational institutes in India, …
Logo
Discovered: 2026-05-14 (3mo ago)
Stride Learning Should've Paid the ransom. We were only asking $500,000 in bitcoin or monero it's no…
Logo
Discovered: 2026-05-14 (3mo ago)
Amplify technology has been a victim of an attack. There project they were working on with the pakis…
Logo
Discovered: 2026-05-14 (3mo ago)
ShadowByt3$ has breached University of Georgia. The full data is on are leak site. We stole approxim…
Logo
Discovered: 2026-05-14 (3mo ago)
We are ShadowByt3$. We have claimed responsibility for hacking Hotelogix. They have been breached th…
Logo
Discovered: 2026-02-25 (6mo ago)  ·  Attack est.: 2026-02-17
File: UMSA_LEAK.7z…