Last seven days
- First activity
- Aug 26, 2026
- Last activity
- Sep 2, 2026
- Feed role
- C2 / Distribution
- Host form
- 21 IP / 21 hostnames
Shade, also widely known as Troldesh and detected by some vendors as Encoder.858, is a long-running Windows ransomware family first observed in 2014 and active until its operators announced a shutdown at the end of 2019.
Profile source: Mallory opens in a new tabShade
Shade, also widely known as Troldesh and detected by some vendors as Encoder.858, is a long-running Windows ransomware family first observed in 2014 and active until its operators announced a shutdown at the end of 2019. It became one of the more prevalent file-encrypting threats in Russia, but infection activity was also observed internationally, including significant targeting outside Russian-speaking regions. The malware primarily targeted Microsoft Windows systems and was distributed through malicious spam campaigns and, at various times, exploit kits such as Nuclear and Spelevo-associated delivery chains.
Shade was commonly delivered through malspam using invoice-, order-, tax-, or banking-themed lures. Campaigns frequently used ZIP archives containing JavaScript downloaders, and later variants also used PDF attachments that linked victims to ZIP downloads. When executed, the script-based first stage retrieved the ransomware payload from compromised websites and launched it on the victim host. Some campaigns relied on compromised WordPress infrastructure, and reporting tied parts of the delivery ecosystem to automated brute-force attacks against website administration panels.
On execution, Shade encrypted files on local systems and used multiple extension schemes over its lifetime, including xtbl, ytbl, no_more_ransom, and crypted000007. It dropped multiple ransom-note text files and changed the desktop background to announce the attack. Ransom instructions were commonly presented in both Russian and English and directed victims to Tor-based payment or contact infrastructure. Technical reporting also describes Shade using AES-256 for file encryption with RSA-3072-protected key material, and falling back to embedded public keys if command-and-control communication was unavailable.
Beyond ransomware behavior, Shade also acted as a downloader for additional malware. It could continue running after encryption, contact Tor-based command-and-control services, collect host and system information, and retrieve further payloads. Documented follow-on malware associated with Shade infections included CMSBrute, Muref, Kovter, and Zemot. Some observed infections also generated secondary malicious traffic such as WordPress brute-force activity and click-fraud-like web requests, indicating broader post-compromise monetization beyond file encryption alone.
Operational reporting suggests Shade maintained relatively stable core behavior for years, with changes focused more on encrypted filename formats, keys, and infrastructure than on major redesigns. Researchers also assessed that its distribution may have involved a partnership or affiliate-style model based on differing build identifiers, contact details, and infrastructure overlaps. In 2020, the operators publicly stated they had ceased operations and released a large set of decryption keys, which were validated by defenders and enabled broad recovery for many historical victims.
C2 tracking
Derp observations, rolling seven-day window
Samples
49d7c6c1ad16595c2695a17bd7552b8754dcb9a744a2bb436800c751720952b7 5ed7fd177ce9768ec67e1b6feb23fddb258e7ae25dd730239a807d020deb35c2 8d9aed2ea77f3bd9912cc598f0d2956e46d6147b8b4f50cf54b021f9f9bc0aaf a6234024b31a0011fc13f2bcda5a06c3e2aac4cf18ac7a27b22baed5a2734c66 ea8287cfb278d9590ea31d44d8451c413d09e7a27072063a6bc65d98ca1f87f2 897f1cbe4f6f19ab081ba382a8d8b2663902d36aded97aecabe8985dc150ae86 1b723594e574c00aac2c946ff738a0454f7c24f6ebc84ae45a6af9628b08cb96 2b20eb4237ad2eab05c4a2ad261bcfd436663cf32e2a45526e17dfd3a51a095d 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 508e710d673802a532798e7dffa3aefcfb36eff0acef1620b8614917ac62e53e Reported operators
Campaign: ไบบ็ฑปๅ่ฃ(Mankind) ... Observed commodity malware: Phorpiex, and Shade
MITRE ATT&CK
Reporting
Shade, also known as Troldesh and Encoder.858, remained an active Windows ransomware threat through 2019, spreading largely through malspam that impersonated invoices, bills, and order-related correspondence. Multiple campaigns used ZIP archives or PDFs linking to ZIP downloads that contained malicious JavaScript downloaders, which fetched additional payloads from compromised servers and ultimately deployed the ransomware. Researchers reported the malware consistently appended the .crypted000007 extension, used Tor-based payment and decryption infrastructure, and in some cases relied on fake Comodo-issued signatures and files masquerading as csrss.exe to evade detection. Telemetry and campaign reporting showed Shade hitting Russian-speaking users as well as victims in the United States, Japan, India, Thailand, Canada, Ukraine, France, and Germany, with high-tech, wholesale and retail, and education among the most affected sectors. After operating since 2014 and maintaining broadly similar tactics for years, the operators announced they had ended distribution at the close of 2019 and released more than 750,000 decryption keys. Kaspersky validated the keys and published a free decryptor, and recovery assistance also became available through the No More Ransom project.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.