Tengu Ransomware, later rebranded as Shisa Ransomware in March 2026, is a financially motivated ransomware-as-a-service operation first observed in October 2025. The group uses a double-extortion model, stealing data before encrypting systems, and operated a structured affiliate program with disciplined management. In fewer than six months it claimed roughly 50 victims across multiple regions and was noted for geographically diverse targeting, including activity across North America, Europe, Asia, the Middle East, Africa, and Latin America. Tengu is assessed as sector-agnostic, with technology and manufacturing among the most affected sectors, and it has also been observed targeting construction, government, police, banking, transportation-related, and power-sector organizations in regional reporting. Early victimology showed concentration in the Middle East and North Africa before expansion into broader global targeting. The operation has been linked to victims in countries including the United States, Indonesia, Mexico, India, Italy, Qatar, Morocco, the United Arab Emirates, Spain, Brazil, Japan, and Thailand. The group provides ransomware builds for Windows, Linux, and ESXi and has used intermittent encryption to accelerate impact. Its affiliate ecosystem has used custom exfiltration tooling in addition to common transfer utilities and cloud or remote storage destinations. Tengu maintained a Tor-based leak site featuring stolen data, countdown timers, and at times ransom negotiation chat logs, consistent with mature leak-site operations. Observed intrusion tradecraft includes brute-force attacks against exposed remote services, spearphishing, exploitation of public-facing applications, and reuse of valid credentials from prior breaches. In at least one confirmed case, affiliates exploited CVE-2020-1472 to obtain domain administrator privileges. Post-compromise behavior includes credential abuse, use of living-off-the-land binaries, disabling security controls, clearing logs, deleting shadow copies, and encrypting victim environments. Reporting also ties at least one victim later claimed by Tengu to prior compromise by a Russian-speaking initial access broker, indicating that some Tengu intrusions may rely on purchased or brokered access. Known aliases include Tengu and Tengu Ransomware, and the operation later adopted the name Shisa Ransomware.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a group with no Q2 industrial claims.
Named as another ransomware group that claimed a victim weeks after the operator's compromise, reinforcing the pattern of access being sold or transferred to downstream extortion actors.
Active ransomware crew operating across META nations during Q1 2026.
Financially motivated RaaS operation conducting double-extortion ransomware attacks, stealing data before encryption, managing affiliates through a structured program, and later rebranding from Tengu to Shisa.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.