Skip to content

Shade

Shade, also widely known as Troldesh and detected by some vendors as Encoder.858, is a long-running Windows ransomware family first observed in 2014 and active until its operators announced a shutdown at the end of 2019.

Profile source: Mallory opens in a new tab

Shade

Family profile

Shade, also widely known as Troldesh and detected by some vendors as Encoder.858, is a long-running Windows ransomware family first observed in 2014 and active until its operators announced a shutdown at the end of 2019. It became one of the more prevalent file-encrypting threats in Russia, but infection activity was also observed internationally, including significant targeting outside Russian-speaking regions. The malware primarily targeted Microsoft Windows systems and was distributed through malicious spam campaigns and, at various times, exploit kits such as Nuclear and Spelevo-associated delivery chains.

Shade was commonly delivered through malspam using invoice-, order-, tax-, or banking-themed lures. Campaigns frequently used ZIP archives containing JavaScript downloaders, and later variants also used PDF attachments that linked victims to ZIP downloads. When executed, the script-based first stage retrieved the ransomware payload from compromised websites and launched it on the victim host. Some campaigns relied on compromised WordPress infrastructure, and reporting tied parts of the delivery ecosystem to automated brute-force attacks against website administration panels.

On execution, Shade encrypted files on local systems and used multiple extension schemes over its lifetime, including xtbl, ytbl, no_more_ransom, and crypted000007. It dropped multiple ransom-note text files and changed the desktop background to announce the attack. Ransom instructions were commonly presented in both Russian and English and directed victims to Tor-based payment or contact infrastructure. Technical reporting also describes Shade using AES-256 for file encryption with RSA-3072-protected key material, and falling back to embedded public keys if command-and-control communication was unavailable.

Beyond ransomware behavior, Shade also acted as a downloader for additional malware. It could continue running after encryption, contact Tor-based command-and-control services, collect host and system information, and retrieve further payloads. Documented follow-on malware associated with Shade infections included CMSBrute, Muref, Kovter, and Zemot. Some observed infections also generated secondary malicious traffic such as WordPress brute-force activity and click-fraud-like web requests, indicating broader post-compromise monetization beyond file encryption alone.

Operational reporting suggests Shade maintained relatively stable core behavior for years, with changes focused more on encrypted filename formats, keys, and infrastructure than on major redesigns. Researchers also assessed that its distribution may have involved a partnership or affiliate-style model based on differing build identifiers, contact details, and infrastructure overlaps. In 2020, the operators publicly stated they had ceased operations and released a large set of decryption keys, which were validated by defenders and enabled broad recovery for many historical victims.

Capabilities

  • Brute Force
  • Defense Evasion
  • Exfiltration
  • Extortion
  • Post Exploitation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 26, 2026
Last activity
Sep 2, 2026
Feed role
C2 / Distribution
Host form
21 IP / 21 hostnames

Leading locations

  • US9
  • CN5
  • NL4
  • DE3
  • SG2
  • AT1
  • CA1
  • IE1
  • KR1
  • LU1
  • RU1
  • SE1

Leading providers

  • Cloudflare, Inc.3
  • Hangzhou Alibaba Advertising Co.,Ltd.3
  • Omegatech LTD3
  • Amazon.com, Inc.2
  • 453 Ladplacout Jorakhaebua1
  • Akamai Connected Cloud1

Infrastructure traits

  • Hosting 24
  • Anycast 4

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
menuPass

Campaign: ไบบ็ฑปๅˆ†่ฃ‚(Mankind) ... Observed commodity malware: Phorpiex, and Shade

MITRE ATT&CK

Shade in ATT&CK

17 distinct techniques

Reporting

Research mentioning Shade

Jan 1
Malware Traffic Analysis

Malware-Traffic-Analysis.net - 2017-03-03 - Shade (Troldesh) ransomware infection

Shade, also known as Troldesh and Encoder.858, remained an active Windows ransomware threat through 2019, spreading largely through malspam that impersonated invoices, bills, and order-related correspondence. Multiple campaigns used ZIP archives or PDFs linking to ZIP downloads that contained malicious JavaScript downloaders, which fetched additional payloads from compromised servers and ultimately deployed the ransomware. Researchers reported the malware consistently appended the .crypted000007 extension, used Tor-based payment and decryption infrastructure, and in some cases relied on fake Comodo-issued signatures and files masquerading as csrss.exe to evade detection. Telemetry and campaign reporting showed Shade hitting Russian-speaking users as well as victims in the United States, Japan, India, Thailand, Canada, Ukraine, France, and Germany, with high-tech, wholesale and retail, and education among the most affected sectors. After operating since 2014 and maintaining broadly similar tactics for years, the operators announced they had ended distribution at the close of 2019 and released more than 750,000 decryption keys. Kaspersky validated the keys and published a free decryptor, and recovery assistance also became available through the No More Ransom project.

Jun 11
Support Kaspersky

The Kaspersky ShadeDecryptor tool for decrypting files affected by Trojan-Ransom.Win32.Shade

Apr 27
Zdnet Zero Day

Shade (Troldesh) ransomware shuts down and releases decryption keys | ZDNET

Jun 25
Avast

Ransomware Strain Troldesh Spikes Again - Avast

May 22
Palo Alto Networks Unit 42

Shade Ransomware Hits High-Tech, Wholesale, Education Sectors in U.S, Japan, India, Thailand, Canada

Feb 20
Sans Isc

More Russian language malspam pushing Shade (Troldesh) ransomware

Jan 28
Eset Welivesecurity

Russia hit by new wave of ransomware spam

Nov 29
Sans Isc

Russian language malspam pushing Shade (Troldesh) ransomware

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.