# SHADOWBYT3$

> As of 2026-09-30, SHADOWBYT3$ is a threat actor tracked by Threadlinqs Intelligence across 2 threats spanning threat intel, data breach. ATT&CK coverage spans 20 techniques across 9 tactics in 2 of 2 tracked threats. Most-observed techniques: T1078 (Valid Accounts), T1199 (Trusted Relationship), T1213 (Data from Information Repositories).

- **Tracked threats:** 2
- **Categories:** THREAT_INTEL, DATA_BREACH
- **As of:** 2026-09-30

## ATT&CK techniques observed

20 techniques observed across 2 of 2 tracked threats. Tactics: Resource Development (4), Collection (3), Initial Access (3), Reconnaissance (3), Credential Access (2), Exfiltration (2).

- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 2 of 2 tracked threats
- [T1199](https://intel.threadlinqs.com/technique/T1199) Trusted Relationship — Initial Access — observed in 2 of 2 tracked threats
- [T1213](https://intel.threadlinqs.com/technique/T1213) Data from Information Repositories — Collection — observed in 2 of 2 tracked threats
- [T1589](https://intel.threadlinqs.com/technique/T1589) Gather Victim Identity Information — Reconnaissance — observed in 2 of 2 tracked threats
- [T1591](https://intel.threadlinqs.com/technique/T1591) Gather Victim Org Information — Reconnaissance — observed in 2 of 2 tracked threats
- [T1657](https://intel.threadlinqs.com/technique/T1657) Financial Theft — Impact — observed in 2 of 2 tracked threats
- [T1048](https://intel.threadlinqs.com/technique/T1048) Exfiltration Over Alternative Protocol — Exfiltration — observed in 1 of 2 tracked threats
- [T1119](https://intel.threadlinqs.com/technique/T1119) Automated Collection — Collection — observed in 1 of 2 tracked threats
- [T1190](https://intel.threadlinqs.com/technique/T1190) Exploit Public-Facing Application — Initial Access — observed in 1 of 2 tracked threats
- [T1451](https://attack.mitre.org/techniques/T1451/) SIM Card Swap — Initial Access (Mobile) — observed in 1 of 2 tracked threats
- [T1526](https://intel.threadlinqs.com/technique/T1526) Cloud Service Discovery — Discovery — observed in 1 of 2 tracked threats
- [T1530](https://intel.threadlinqs.com/technique/T1530) Data from Cloud Storage — Collection — observed in 1 of 2 tracked threats
- [T1555](https://intel.threadlinqs.com/technique/T1555) Credentials from Password Stores — Credential Access — observed in 1 of 2 tracked threats
- [T1567](https://intel.threadlinqs.com/technique/T1567) Exfiltration Over Web Service — Exfiltration — observed in 1 of 2 tracked threats
- [T1583](https://intel.threadlinqs.com/technique/T1583) Acquire Infrastructure — Resource Development — observed in 1 of 2 tracked threats

## Tracked threats

- [Insiders for Hire: Underground Market for Employee Access Expands Beyond Privileged IT Roles](https://intel.threadlinqs.com/threat/TL-2026-2799) — MEDIUM
- [SHADOWBYT3$ Claims Breach of Nintendo via Third-Party TINYpulse HR-Engagement SaaS Exposure (~859 MB, $2M Extortion)](https://intel.threadlinqs.com/threat/TL-2026-0808) — MEDIUM

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/SHADOWBYT3%24
