Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Shade has been distributed through malicious spam (malspam) and exploit kits.
The malicious spam (malspam) has a link to a zip archive containing a .js file.
Searching through VirusTotal Intelligence, I found Russian language malspam with attached zip archives pushing Shade/Troldesh ransomware... Victims would open the attached zip archive, then they would need to double-click the JavaScript (.js) file contained in the archive.
106 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware that encrypts files and can lock victims out of their computers; the content says it was previously spread by phishing emails and is reportedly being spread via social networks and messaging platforms linking to malicious content.
Troldesh is a ransomware family that encrypts a victim’s personal files, renames them with .xtbl/.xbtl extensions, drops ransom notes such as README[number].txt, and extorts payment via direct email communication with victims in exchange for decryption.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.