ShadowByt3$ is a cyber-extortion actor also known as ShadowByt3 and ShadowByt3s. Its publicly documented activity in 2026 centers on extortion-site victim listings, claims of stolen organizational data, and threats to publish that data unless victims enter negotiations within specified deadlines. Its claimed targets span real estate and property management, healthcare and medical technology, software and IT services, agriculture and food production, and consumer-facing businesses. The actor uses threatened disclosure and reputational damage to pressure organizations. It listed Abbott Laboratories in connection with the company's externally hosted LabCentral technical-documentation portal; Abbott disputed the characterization of the documents as sensitive or proprietary. Many of the actor's victim claims remain independently unverified, and some listings have been flagged as potentially fabricated. Confirmed ransomware encryption, a ransomware-as-a-service operating model, specific intrusion techniques, organizational structure, and geographic origin have not been established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
23 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Alleged ransomware and extortion operation against HandyTrac Greystar AZ WARNING. The group claims to have locked out personnel, deleted or disabled access, controlled administrative portals, and exfiltrated physical-to-digital key maps, property intelligence and vulnerability logs, employee identity and credential data, and financial/vendor records.
ShadowByt3$ claims to have locked out staff associated with HandyTrac/Greystar in Arizona and exfiltrated key-control, employee credential, financial/vendor, and administrative-portal material. The group set a negotiation deadline of September 22, 2026, at 3:00 PM and linked alleged lockout screenshots, but did not state a ransom amount or data volume.
Alleged ransomware/extortion operation against HandyTrac. The group claims theft of physical-to-digital key maps, property intelligence and vulnerability logs, employee identity and credential data, financial and vendor records, and administrative portal-control information, and threatens public disclosure if the victim does not negotiate.
ShadowByt3$ claims to have compromised HandyTrac (Greystar Litchfield Park, Arizona) and exfiltrated sensitive property-security, employee, financial, vendor, and administrative data. The group threatens to release the complete dataset unless negotiations occur within 72 hours and provides an alleged screenshot proof link.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.