Shadow Hacker is a hack-for-hire operation active on Tor hidden services and closely linked to the similarly branded Anonymous Hackers service. The operation advertises illicit intrusion services including website compromise, distributed denial-of-service attacks, social media account takeover, database extraction, email compromise, phone monitoring, background checks, and purported cryptocurrency recovery. Multiple Shadow Hacker and Anonymous Hackers sites have exhibited overlapping operational characteristics, including similar site structure, service catalogs, communication patterns, rotating contact infrastructure, and use of multiple PGP identities, indicating an interconnected or closely related service ecosystem rather than clearly distinct actors. The operation appears to maintain resilience through frequent infrastructure churn across multiple hidden services and communication channels. Historical and concurrent Shadow Hacker-branded sites have presented near-identical layouts and offerings, and some infrastructure linked from Shadow Hacker artifacts has led to Anonymous Hackers-branded services with substantially similar content. This pattern is consistent with a flexible commercial cybercrime service model designed to preserve continuity as sites disappear or are replaced. Observed capabilities center on offensive access-for-hire and disruption services rather than espionage or ransomware. Advertised activities support assessment of capabilities including initial access, distributed denial-of-service, credential theft, exfiltration, and post-exploitation. The actor also demonstrates operational security awareness through rotating domains, email accounts, and cryptographic identifiers to complicate attribution and service tracking. High-confidence attribution to a specific country or state sponsor is not available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.