Last seven days
- First activity
- Sep 2, 2026
- Last activity
- Sep 9, 2026
- Feed role
- C2 / Distribution
- Host form
- 7 IP / 8 hostnames
Shade, also widely known as Troldesh and detected by some vendors as Encoder.858, is a long-running Windows ransomware family first observed in 2014 and active until its operators announced a shutdown at the end of 2019.
Profile source: Mallory opens in a new tabShade
Shade, also widely known as Troldesh and detected by some vendors as Encoder.858, is a long-running Windows ransomware family first observed in 2014 and active until its operators announced a shutdown at the end of 2019. It became one of the more prevalent file-encrypting threats in Russia, but infection activity was also observed internationally, including significant targeting outside Russian-speaking regions. The malware primarily targeted Microsoft Windows systems and was distributed through malicious spam campaigns and, at various times, exploit kits such as Nuclear and Spelevo-associated delivery chains.
Shade was commonly delivered through malspam using invoice-, order-, tax-, or banking-themed lures. Campaigns frequently used ZIP archives containing JavaScript downloaders, and later variants also used PDF attachments that linked victims to ZIP downloads. When executed, the script-based first stage retrieved the ransomware payload from compromised websites and launched it on the victim host. Some campaigns relied on compromised WordPress infrastructure, and reporting tied parts of the delivery ecosystem to automated brute-force attacks against website administration panels.
On execution, Shade encrypted files on local systems and used multiple extension schemes over its lifetime, including xtbl, ytbl, no_more_ransom, and crypted000007. It dropped multiple ransom-note text files and changed the desktop background to announce the attack. Ransom instructions were commonly presented in both Russian and English and directed victims to Tor-based payment or contact infrastructure. Technical reporting also describes Shade using AES-256 for file encryption with RSA-3072-protected key material, and falling back to embedded public keys if command-and-control communication was unavailable.
Beyond ransomware behavior, Shade also acted as a downloader for additional malware. It could continue running after encryption, contact Tor-based command-and-control services, collect host and system information, and retrieve further payloads. Documented follow-on malware associated with Shade infections included CMSBrute, Muref, Kovter, and Zemot. Some observed infections also generated secondary malicious traffic such as WordPress brute-force activity and click-fraud-like web requests, indicating broader post-compromise monetization beyond file encryption alone.
Operational reporting suggests Shade maintained relatively stable core behavior for years, with changes focused more on encrypted filename formats, keys, and infrastructure than on major redesigns. Researchers also assessed that its distribution may have involved a partnership or affiliate-style model based on differing build identifiers, contact details, and infrastructure overlaps. In 2020, the operators publicly stated they had ceased operations and released a large set of decryption keys, which were validated by defenders and enabled broad recovery for many historical victims.
C2 tracking
Derp observations, rolling seven-day window
Samples
29f281e0e9ebc9cc7b54af08535509feac1930a60d3d2e2fe9528f77711f04a8 4cb5aa48159039802920e727630baa8605b89fa680c8296a4220a3c431a0d7ac 6ec6204ceb39cc235927feb55c6c78a029f051b8770cd8f6823bf2eaeb9f8409 7c0dcc80d059cebeb8a803f7455f008a1561737b7f6b1bbaa249b51799ba1ca7 96d443a8f6fbb22ef7a1462d57b39591cbd465ba391a8c6e2c41fa3df7f92f0c dbee15d75e4bfc40a0091878009dedf0cca795f224554c91ad776710eb3a76a9 1b723594e574c00aac2c946ff738a0454f7c24f6ebc84ae45a6af9628b08cb96 40b643468356c0fd751893647ad0dc9e2a0019427e4f5f0e2f6e559efcecb977 508e710d673802a532798e7dffa3aefcfb36eff0acef1620b8614917ac62e53e 9f0a4fce6d13c892326cf6788258b035118901d2551e43cc214083acc7ff2a24 Reported operators
Campaign: δΊΊη±»εθ£(Mankind) ... Observed commodity malware: Phorpiex, and Shade
MITRE ATT&CK
Reporting
Shade, also known as Troldesh and Encoder.858, remained an active Windows ransomware threat through 2019, spreading largely through malspam that impersonated invoices, bills, and order-related correspondence. Multiple campaigns used ZIP archives or PDFs linking to ZIP downloads that contained malicious JavaScript downloaders, which fetched additional payloads from compromised servers and ultimately deployed the ransomware. Researchers reported the malware consistently appended the .crypted000007 extension, used Tor-based payment and decryption infrastructure, and in some cases relied on fake Comodo-issued signatures and files masquerading as csrss.exe to evade detection. Telemetry and campaign reporting showed Shade hitting Russian-speaking users as well as victims in the United States, Japan, India, Thailand, Canada, Ukraine, France, and Germany, with high-tech, wholesale and retail, and education among the most affected sectors. After operating since 2014 and maintaining broadly similar tactics for years, the operators announced they had ended distribution at the close of 2019 and released more than 750,000 decryption keys. Kaspersky validated the keys and published a free decryptor, and recovery assistance also became available through the No More Ransom project.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.