Shadow is a financially motivated ransomware operation that has targeted large industrial enterprises in Russia since at least March 2023. The group has also operated under the names Comet and DARKSTAR. It encrypts Windows systems using LockBit 3-derived ransomware and Linux systems using a Babuk-derived encryptor. Shadow uses vulnerable public-facing services, including exposed RDP, for initial access; AnyDesk and ngrok have also been used for unauthorized remote access. The operation conducts data theft before encryption and uses double extortion, demanding payment for decryption while threatening to release or sell stolen data through third-party resources. Victim negotiations are conducted through Tor-hosted chat panels using victim-specific access credentials. Shadow has made multimillion-ruble ransom demands. F.A.C.C.T. assessed that Shadow, Comet, and DARKSTAR are successive brands of the same operation and linked its operators to the hacktivist group Twelve. Under the Twelve identity, the same operators have conducted destructive attacks against Russian organizations rather than primarily financially motivated extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an apparently inactive peer group that had operated a leak site.
Ransomware/extortion group attacking organizations in Russia. The group has rebranded multiple times from Shadow to Comet and then DARKSTAR, while maintaining the same tactics and tooling. It also appears linked to the hacktivist persona Twelve, which uses similar TTPs against Russian organizations with destructive rather than financial objectives.
A newly observed ransomware group attacking large Russian companies, especially major industrial enterprises, using double-extortion tactics with Tor-based victim chat panels and demanding $1–2 million in ransom.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.