ShadowCoil is a cybercriminal threat actor identified as a former affiliate of the RansomHub ransomware ecosystem. The actor has been associated with the use and distribution of a credential-harvesting tool, indicating an operational focus on obtaining victim credentials to support follow-on intrusion activity. This places ShadowCoil within the broader financially motivated ransomware affiliate landscape, where credential access commonly enables initial compromise and subsequent monetization. High-confidence reporting directly ties the actor to credential theft activity and to its prior affiliation with RansomHub; additional targeting, geographic attribution, and broader tradecraft details are not currently available at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ShadowCoil, a former affiliate of RansomHub, is deploying credential harvesting tools, indicating a focus on stealing authentication data for further attacks or resale.
ShadowCoil, a former affiliate of RansomHub, is deploying credential harvesting tools, indicating a focus on stealing authentication data for further attacks or resale.
ShadowCoil, a former affiliate of RansomHub, is deploying credential harvesting tools.
ShadowCoil, a former affiliate of RansomHub, is deploying credential harvesting tools.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.