Shade, also widely known as Troldesh and detected by some vendors as Encoder.858, is a long-running Windows ransomware family first observed in 2014 and active until its operators announced a shutdown at the end of 2019. It became one of the more prevalent file-encrypting threats in Russia, but infection activity was also observed internationally, including significant targeting outside Russian-speaking regions. The malware primarily targeted Microsoft Windows systems and was distributed through malicious spam campaigns and, at various times, exploit kits such as Nuclear and Spelevo-associated delivery chains.
Shade was commonly delivered through malspam using invoice-, order-, tax-, or banking-themed lures. Campaigns frequently used ZIP archives containing JavaScript downloaders, and later variants also used PDF attachments that linked victims to ZIP downloads. When executed, the script-based first stage retrieved the ransomware payload from compromised websites and launched it on the victim host. Some campaigns relied on compromised WordPress infrastructure, and reporting tied parts of the delivery ecosystem to automated brute-force attacks against website administration panels.
On execution, Shade encrypted files on local systems and used multiple extension schemes over its lifetime, including xtbl, ytbl, no_more_ransom, and crypted000007. It dropped multiple ransom-note text files and changed the desktop background to announce the attack. Ransom instructions were commonly presented in both Russian and English and directed victims to Tor-based payment or contact infrastructure. Technical reporting also describes Shade using AES-256 for file encryption with RSA-3072-protected key material, and falling back to embedded public keys if command-and-control communication was unavailable.
Beyond ransomware behavior, Shade also acted as a downloader for additional malware. It could continue running after encryption, contact Tor-based command-and-control services, collect host and system information, and retrieve further payloads. Documented follow-on malware associated with Shade infections included CMSBrute, Muref, Kovter, and Zemot. Some observed infections also generated secondary malicious traffic such as WordPress brute-force activity and click-fraud-like web requests, indicating broader post-compromise monetization beyond file encryption alone.
Operational reporting suggests Shade maintained relatively stable core behavior for years, with changes focused more on encrypted filename formats, keys, and infrastructure than on major redesigns. Researchers also assessed that its distribution may have involved a partnership or affiliate-style model based on differing build identifiers, contact details, and infrastructure overlaps. In 2020, the operators publicly stated they had ceased operations and released a large set of decryption keys, which were validated by defenders and enabled broad recovery for many historical victims.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Campaign: 人类分裂(Mankind) ... Observed commodity malware: Phorpiex, and Shade
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Shade has been distributed through malicious spam (malspam) and exploit kits.
The malicious spam (malspam) has a link to a zip archive containing a .js file.
Searching through VirusTotal Intelligence, I found Russian language malspam with attached zip archives pushing Shade/Troldesh ransomware... Victims would open the attached zip archive, then they would need to double-click the JavaScript (.js) file contained in the archive.
107 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware delivered via a malicious spam campaign using a ZIP archive containing a disguised JavaScript file. On execution, it dropped Shade/Troldesh, encrypted files on the infected Windows host, and used the .no_more_ransom extension for encrypted files.
Ransomware that encrypts files on the victim device, making them inaccessible; Kaspersky's ShadeDecryptor attempts to recover files by locating a matching decryption key in its database or via server lookup.
Commodity ransomware/malware observed in a suspected Stone Panda-linked campaign targeting engineering, shipping/container technology, and electrical equipment companies for intellectual property and trade secret theft.
Ransomware family previously delivered via Spelevo Exploit Kit.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.