ShadowByte$ is a threat actor name associated with an alleged data-theft extortion incident targeting Nintendo. The actor claimed to possess approximately 859 MB of internal data spanning multiple years and demanded a ransom to prevent public release. Available reporting indicates the purported dataset included human-resources and employee-engagement material such as workforce surveys, employee feedback records, internal analytics, performance metrics, exported reports, and planning documents. Independent review of limited leaked samples suggested that at least some material appeared credible, but the full scope, authenticity, and intrusion path were not conclusively established. It remained unclear whether Nintendo itself was directly compromised or whether the data was obtained through a third-party service provider connected to employee-engagement functions. Based on currently available high-confidence information, ShadowByte$ is best characterized as an extortion-oriented actor engaged in alleged theft and threatened disclosure of corporate data. No reliable attribution to a nation-state, broader intrusion set, or established sub-groups is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.