Shanya is a packer-as-a-service malware offering used to provide obfuscation, anti-detection, and defense-evasion capabilities to ransomware operators. It functions primarily as an endpoint detection and response killer, using a combination of a legitimate driver and a malicious unsigned kernel driver to gain the ability to terminate and remove security processes on compromised systems. This enables follow-on ransomware deployment and reduces the likelihood of detection and interruption during intrusion operations. Shanya has been associated with multiple ransomware groups, including Akira, Medusa, Qilin, and Crytox, indicating use across the broader ransomware-as-a-service ecosystem rather than by a single closed actor. It has also been observed in social-engineering-driven intrusion chains such as Booking.com-themed ClickFix activity and in malware delivery involving CastleRAT through DLL side-loading. Its emergence reflects the increasing specialization of criminal tooling providers that supply post-compromise capabilities to financially motivated intrusion actors. Shanya is best characterized as a criminal enablement service within the ransomware ecosystem rather than a nation-state threat actor. Its known role centers on defense evasion and post-exploitation support for ransomware operations, especially by disabling security tooling to facilitate payload execution and subsequent attacker actions.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.