ShadowByt3$ is a cybercriminal extortion group that emerged in late 2025 and presents itself as an "extortion-as-a-service" operation. Publicly attributed activity indicates a primary focus on data theft and coercive monetization rather than confirmed widespread file encryption. The group has operated a data leak site, later announced its retirement, and has been discussed in the context of possible ransomware-as-a-service activity, though the strongest corroborated pattern is theft-and-extortion. Observed victim claims link ShadowByt3$ to incidents affecting healthcare and life sciences, agriculture technology, education-related services, and technology companies. Reported cases include claims involving Abbott’s LabCentral portal, Cropwise of Syngenta Group, Leadership Boulevard, and employee data associated with Nintendo through the third-party TinyPulse platform. In multiple cases, the group claimed to have stolen internal or employee-related information and then issued short negotiation deadlines backed by threats of public disclosure. In at least one campaign, the group redirected pressure from a primary brand target to a third-party service provider after nonpayment. Tactics attributed to ShadowByt3$ include use of compromised credentials for initial access, exploitation of an unspecified environmental weakness, theft of documents and employee records, and operation of a leak site to pressure victims. The group has explicitly described itself as extortion-focused and has threatened public leaks, outreach to affected individuals, and other coercive measures. Claims tied to the Abbott incident indicate access via compromised customer credentials to an externally hosted portal and exfiltration of technical and regulatory documentation. Claims tied to Cropwise and Nintendo indicate theft of identity data, employee records, survey content, financial or tax-related documents, and operational information. Public reporting also associates the group with leak-site postings and ransom demands in the low-million-dollar range. Aliases in use include ShadowByt3$ and shadowbyt3. Available evidence supports classification as a financially motivated cyber extortion actor with data-theft and leak-based pressure as its defining tradecraft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed access to Abbott's LabCentral portal using compromised customer credentials and an unspecified weakness, and alleged exfiltration of technical and regulatory documentation related to Abbott lab systems.
Claimed responsibility for a separate Abbott LabCentral intrusion using compromised customer credentials and an unspecified weakness, allegedly exfiltrating technical and regulatory documentation related to Abbott lab systems.
Claimed breach of Abbott's Core Laboratory diagnostics business through the LabCentral customer portal using compromised credentials, allegedly stealing technical specifications and regulatory documentation.
Claimed responsibility for one of the reported Abbott breach incidents.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.