Shadow is a ransomware and extortion group active since at least March 2023 that targets Russian organizations, particularly large industrial enterprises. It subsequently operated under the names Comet and DARKSTAR, adopting Comet in September 2023 and DARKSTAR in January 2024. Its operators have also been identified as the group behind Twelve, a hacktivist identity associated with destructive attacks against Russian organizations rather than financial extortion. The group's country of origin is not established. Shadow gains initial access through vulnerable public-facing services, including RDP servers, and uses AnyDesk and ngrok for unauthorized remote access. It encrypts Windows environments with LockBit 3, also known as LockBit Black, and Linux systems with a Babuk-based encryptor, drawing on publicly available ransomware code. Its operations combine encryption with threats to disclose stolen data, and stolen information has also been advertised for sale on third-party resources. Victims negotiate through Tor-hosted chat panels accessed with individual keys supplied in ransom notes. Reported ransom demands have ranged from $1 million to $2 million, with one demand reaching approximately $3.5 million. Its remote-access tooling and ransomware families remained consistent across its rebrandings.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an apparently inactive peer group that had operated a leak site.
Ransomware/extortion group attacking organizations in Russia. The group has rebranded multiple times from Shadow to Comet and then DARKSTAR, while maintaining the same tactics and tooling. It also appears linked to the hacktivist persona Twelve, which uses similar TTPs against Russian organizations with destructive rather than financial objectives.
A newly observed ransomware group attacking large Russian companies, especially major industrial enterprises, using double-extortion tactics with Tor-based victim chat panels and demanding $1–2 million in ransom.
Mentioned as a pro-Ukrainian group with a political dimension, providing a comparison with Masque. No specific operations, tools, or vulnerabilities are attributed to Shadow in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.