Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

Shadowbyt3$

| Active | RaaS

ShadowByt3$ is a ransomware-as-a-service group first observed in October 2025, using multi-method extortion and communicating via Telegram and Tox, with a very small confirmed victim list suggesting it remains in early-stage operation.

Victims
12
 
First Discovered
2026-02-25
victim
Last Discovered
2026-06-16
victim
Inactive Since
42
days
Avg Delay
29
days
Infostealer
77.8%
victims with domain
Countries
6
hit
View Victims on World Map View Group Statistics
Attack Velocity — Last 12 months
Exclusive interview with the ransomware group ShadowByt3$ from the CyberSecurityIL Telegram Channel — ransomware-interviews.base44.app

Known Locations (4)
Favicon Title Type Available Last Visit Server Info FQDN
favicon Leaks No 2026-05-24T06:07:15 mfbbt65kir2drc7tuoukwibikgvxquauscnzgbeltkmidjtgqlzm2qad.onion
favicon ShadowByt3$ No 2026-04-28T07:28:57 shadowbyt3s.8bit.ca
favicon SB Group No 2026-07-18T22:42:30 52rtvdymcqvebbamd3la3wtu3ofrcuzuzja3vrsu6wiyrq223osptzqd.onion
favicon SB Data Leak Site No 2026-07-18T22:42:09 shdwbt3ja2ptjt6poluegas44i35727lgmoqqquoww642x3zyocyhuqd.onion

Target
Top 5 Activity Sectors
  • Education 4
  • Technology 3
  • Hospitality 3
  • Professional Services 1
  • Agriculture and Food Production 1
Top 5 Countries
  • US flag United States 3
  • JP flag Japan 2
  • IN flag India 2
  • CH flag Switzerland 1
  • GB flag United Kingdom 1

Heatmap

YARA Rules (1)

Victims (12)
Logo
Discovered: 2026-06-16 (1mo ago)
This will be quick. You don't even want to read the private messages as some will be embarrasing. So…
Logo
Discovered: 2026-06-12 (1mo ago)
proof: https://mega.nz/folder/3kBzQKgR#rIhDePsPMeFpfEGTPopDVQ We are ShadowByt3$ a extortion as a se…
Logo
Discovered: 2026-06-03 (1mo ago)
Company Site: leadschool.in size: 765.9MB This is will be quick. The following schools are affected:…
Logo
Discovered: 2026-06-02 (1mo ago)
We have breached you and gained access to the following portals: https://operations.cropwise.com/d/u…
Logo
Discovered: 2026-05-21 (2mo ago)
Should've not messed with us Hotelogix. We gave you guys numerous times to reach back and proceed wi…
Logo
Discovered: 2026-05-21 (2mo ago)  ·  Attack est.: 2026-04-01
StarBucks Failed to reach out to us and didn't pay even $500,000 when we know they can afford it. It…
Logo
Discovered: 2026-05-14 (2mo ago)
Cloud-based school management and collaboration platform targeting educational institutes in India, …
Logo
Discovered: 2026-05-14 (2mo ago)
Stride Learning Should've Paid the ransom. We were only asking $500,000 in bitcoin or monero it's no…
Logo
Discovered: 2026-05-14 (2mo ago)
Amplify technology has been a victim of an attack. There project they were working on with the pakis…
Logo
Discovered: 2026-05-14 (2mo ago)
ShadowByt3$ has breached University of Georgia. The full data is on are leak site. We stole approxim…
Logo
Discovered: 2026-05-14 (2mo ago)
We are ShadowByt3$. We have claimed responsibility for hacking Hotelogix. They have been breached th…
Logo
Discovered: 2026-02-25 (5mo ago)  ·  Attack est.: 2026-02-17
File: UMSA_LEAK.7z…