Shadowbyt3$

☆ pin
Also known as ShadowByt3$
Reports
14
First seen
May 14, 2026
Last seen
Jul 17, 2026
Motivation
Financial

Relationships

Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.

Targeting

Victim regions
×1
×8
United States×8
India×1
United Kingdom×1

Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.

Top ATT&CK techniques

T1537 Transfer Data to Cloud Account ×1T1566 Phishing ×1T1041 Exfiltration Over C2 Channel ×1T1110 Brute Force ×1T1526 Enumerate Cloud Resources ×1T1567.002 Exfiltration Over Web Service - Exfiltration to Cloud Storage ×1T1005 Data from Local System ×1T1078 Valid Accounts ×1T1087 Account Discovery ×1T1567 Exfiltration Over Web Service ×1T1190 Exploit Public-Facing Application ×1

Indicators

domain ×26hash_sha256 ×7url ×7hash_md5 ×5hash_sha1 ×3ip_v4 ×1

Indicator values are available on Pro and via the API.

Recent reports

This page shows data on a 7-day delay. Free accounts get the full delayed feed; real-time reports, indicators, and the API start at $29/mo.