Tengu Ransomware, later rebranded as Shisa Ransomware in March 2026, is a financially motivated ransomware-as-a-service operation first observed in October 2025. The group operates a double-extortion model, stealing data prior to encryption and publishing victim information through a Tor-based leak site with searchable content, countdown timers, and at times ransom negotiation logs. In fewer than six months of activity, it claimed roughly 50 victims across multiple continents, indicating rapid expansion from early activity in the Middle East, North Africa, Spain, and Brazil into North America, Europe, Asia, and Africa. Tengu maintained a structured affiliate program and provided ransomware builds for Windows, Linux, and ESXi. Its tradecraft emphasized hands-on intrusions, intermittent encryption for speed, and disciplined affiliate management. Reported tooling included custom exfiltration utilities as well as common transfer tools, and affiliates were offered additional capabilities such as endpoint security disruption and multi-chain pivoting. The operation was geographically diverse and sector-agnostic, with technology and manufacturing among the most affected sectors. Initial access was primarily obtained through brute-force attacks against exposed remote services, spearphishing, exploitation of public-facing applications, and reuse of valid credentials from prior breaches. In at least one confirmed intrusion, affiliates exploited CVE-2020-1472 to obtain domain administrator privileges. During execution and defense evasion, operators relied heavily on living-off-the-land binaries and administrative-style activity, including disabling security controls, stopping services, clearing event logs, and deleting shadow copies before encryption. The group’s behavior reflects a mature criminal enterprise focused on monetization through ransomware and data-theft extortion rather than espionage or disruption.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as another ransomware group that claimed a victim weeks after the operator's compromise, reinforcing the pattern of access being sold or transferred to downstream extortion actors.
Active ransomware crew operating across META nations during Q1 2026.
Financially motivated RaaS operation conducting double-extortion ransomware attacks, stealing data before encryption, managing affiliates through a structured program, and later rebranding from Tengu to Shisa.
Geographically diversified ransomware actor with relatively low US victim concentration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.