ShadowByt3$ is a ransomware and data-extortion threat actor also tracked as ShadowByt3 and ShadowByt3s. The group has operated a data-leak site and has publicly claimed intrusions against organizations in real estate, technology, healthcare diagnostics, education-related services, and agribusiness. Its observed extortion model involves claims of data theft followed by deadlines and threats to publish purportedly stolen material if victims do not negotiate. Several of its victim claims have not been independently verified, and some listings have been assessed as potentially fabricated. ShadowByt3$ claimed access to Abbott Laboratories' externally hosted LabCentral portal using compromised customer credentials and an environmental weakness, alleging collection of technical and regulatory documentation. Abbott acknowledged awareness of the potential incident but stated that LabCentral contained publicly available technical reference materials rather than sensitive customer or proprietary business information. The actor has also claimed ransomware-related compromises involving U.S. real-estate organizations, a British property business, an Indonesian agribusiness company, and education-related data. The group announced retirement and closure of its leak site during 2026.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
23 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Alleged ransomware and extortion operation against HandyTrac Greystar AZ WARNING. The group claims to have locked out personnel, deleted or disabled access, controlled administrative portals, and exfiltrated physical-to-digital key maps, property intelligence and vulnerability logs, employee identity and credential data, and financial/vendor records.
Alleged ransomware/extortion operation against HandyTrac. The group claims theft of physical-to-digital key maps, property intelligence and vulnerability logs, employee identity and credential data, financial and vendor records, and administrative portal-control information, and threatens public disclosure if the victim does not negotiate.
Ransomware/extortion group claiming six compromises during week 37 of 2026.
Alleged ransomware/extortion activity targeting Ben Leeds Properties, involving a claim of data theft and a deadline to negotiate to prevent public disclosure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.