Shade, also known as Troldesh and Encoder.858, remained an active Windows ransomware threat through 2019, spreading largely through malspam that impersonated invoices, bills, and order-related correspondence. Multiple campaigns used ZIP archives or PDFs linking to ZIP downloads that contained malicious JavaScript downloaders, which fetched additional payloads from compromised servers and ultimately deployed the ransomware. Researchers reported the malware consistently appended the .crypted000007 extension, used Tor-based payment and decryption infrastructure, and in some cases relied on fake Comodo-issued signatures and files masquerading as csrss.exe to evade detection.
Telemetry and campaign reporting showed Shade hitting Russian-speaking users as well as victims in the United States, Japan, India, Thailand, Canada, Ukraine, France, and Germany, with high-tech, wholesale and retail, and education among the most affected sectors. After operating since 2014 and maintaining broadly similar tactics for years, the operators announced they had ended distribution at the close of 2019 and released more than 750,000 decryption keys. Kaspersky validated the keys and published a free decryptor, and recovery assistance also became available through the No More Ransom project.

TTPs, infrastructure, and targeting history in one profile.
14 events from the most recent confirmed update back to the earliest known activity.
Avast said Troldesh/Shade reached its highest prevalence since January and recorded a notable spike on 2019-06-24, concentrated mainly in Russia and Mexico with smaller spikes in the United Kingdom and Germany. The report also said the ransomware was being spread via social networks and messaging platforms that directed users to malicious links, rather than only through earlier phishing-email campaigns.
In February 2019, defenders observed a tactical change in Russian-language Shade spam: emails attached a PDF containing a link to download a ZIP archive instead of attaching the ZIP directly. The archive still delivered a JavaScript downloader that fetched the ransomware payload.
The operators later stated that they ceased distributing Shade at the end of 2019. This marked the operational end of one of the older long-running ransomware families.
Palo Alto Networks analyzed Shade executable delivery attempts from January 1 through March 31, 2019 and identified 307 samples across 6,536 HTTP sessions. The United States, Japan, India, Thailand, and Canada were the most affected countries in the dataset.
ESET documented a January 2019 campaign distributing Shade ransomware through Russian-language emails with malicious JavaScript attachments. Russia accounted for 52% of detections, with additional impact in Ukraine, France, Germany, and Japan.
After a holiday pause, the October 2018 campaign resumed in mid-January 2019 at roughly double its previous size. The renewed wave used Russian-language emails and ZIP archives containing JavaScript downloaders.
ESET reported that a malicious spam campaign distributing Shade started in October 2018. The operation continued into December before pausing around Christmas.
On 2017-03-03, a Shade (Troldesh) infection was documented that began with an IRS-themed spam email linking to a ZIP archive containing a JavaScript downloader. The infection encrypted files with the .no_more_ransom extension and the analysis published detailed network indicators, dropped files, hashes, and follow-on malware activity including WordPress brute-force attempts.
Since June 2016, Shade-encrypted files were observed using the .crypted000007 extension. Reporting also noted the ransomware's infrastructure and victim messaging remained largely consistent from this period onward.
Kaspersky analyzed Trojan-Ransom.Win32.Shade in October 2015, describing it as a widespread ransomware family in Russia that also downloaded additional malware after encrypting files. The report said Shade was spread via malicious spam and the Nuclear exploit kit and used .xtbl or .ytbl extensions on encrypted files.
On 2015-06-01, Check Point documented Troldesh (also known as Shade/Encoder.858) as a Russia-linked ransomware family spread mainly through spam that encrypted files and used .xtbl/.xbtl-style extensions. The report also highlighted the operators' direct email negotiation with victims, including demands reduced from 250 euros to 12,000 RUB and later 7,000 RUB.
Shade ransomware, also known as Troldesh, was first spotted targeting Windows systems. Later reporting described it as an established ransomware family active since late 2014.
Following the operators' disclosure, Kaspersky confirmed the released Shade keys were valid and published a free decryption tool for victims. Reporting said the keys were believed to cover all versions of Shade.
The Shade operators announced they had shut down and published more than 750,000 decryption keys along with their decryption software in a GitHub repository. They also claimed to have destroyed other operational data, including the malware source code.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 114 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
12 references tracked. Mallory keeps watching after this page renders.
malware-traffic-analysis.net
Open sourcesupport.kaspersky.com
Open sourcezdnet.com
Open sourceblog.avast.com
Open sourcesecurelist.com
Open sourceblog.checkpoint.com
Open sourceurlhaus.abuse.ch
Open sourcenomoreransom.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.