Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-06

SHADOWBYT3$

As of 2026-09-30, SHADOWBYT3$ is a threat actor tracked by Threadlinqs Intelligence across 2 threats spanning threat intel, data breach. ATT&CK coverage spans 20 techniques across 9 tactics in 2 of 2 tracked threats. Most-observed techniques: T1078 (Valid Accounts), T1199 (Trusted Relationship), T1213 (Data from Information Repositories).

Tracked threats
22 medium
First seen
2026-06-15
Last seen
2026-09-30
ATT&CK techniques
20across 2 of 2 threats
Related CVEs
0None referenced
2 tracked threat(s) · Categories: THREAT_INTEL, DATA_BREACH

Activity timeline

SHADOWBYT3$ appears in 2 tracked threats between and ; the busiest month was 2026-06 with 1 report.

ATT&CK techniques observed

20 techniques observed across 2 of 2 tracked threats · Resource Development (4), Collection (3), Initial Access (3), Reconnaissance (3), Credential Access (2), Exfiltration (2)
  • T1078 Valid Accounts — Initial Accessobserved in 2 of 2 tracked threats
  • T1199 Trusted Relationship — Initial Accessobserved in 2 of 2 tracked threats
  • T1213 Data from Information Repositories — Collectionobserved in 2 of 2 tracked threats
  • T1589 Gather Victim Identity Information — Reconnaissanceobserved in 2 of 2 tracked threats
  • T1591 Gather Victim Org Information — Reconnaissanceobserved in 2 of 2 tracked threats
  • T1657 Financial Theft — Impactobserved in 2 of 2 tracked threats
  • T1048 Exfiltration Over Alternative Protocol — Exfiltrationobserved in 1 of 2 tracked threats
  • T1119 Automated Collection — Collectionobserved in 1 of 2 tracked threats
  • T1190 Exploit Public-Facing Application — Initial Accessobserved in 1 of 2 tracked threats
  • T1451 SIM Card Swap — Initial Access (Mobile)observed in 1 of 2 tracked threats
  • T1526 Cloud Service Discovery — Discoveryobserved in 1 of 2 tracked threats
  • T1530 Data from Cloud Storage — Collectionobserved in 1 of 2 tracked threats
  • T1555 Credentials from Password Stores — Credential Accessobserved in 1 of 2 tracked threats
  • T1567 Exfiltration Over Web Service — Exfiltrationobserved in 1 of 2 tracked threats
  • T1583 Acquire Infrastructure — Resource Developmentobserved in 1 of 2 tracked threats

Tracked threats