← Back to all threat actors

shadow

Shadow is a low-profile ransomware group tracked on ransomware monitoring platforms with limited public documentation; specific attribution details regarding its targets, origin, or scale remain sparse in published threat intelligence reports.

How we source and review actor profiles
Motivation
ransomware
Status
Dormant

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
CVECVE-2024-55591 linked to this actor

#StopRansomware: Gunra Ransomware

Cataloged
CVECVE-2025-24472 linked to this actor

#StopRansomware: Gunra Ransomware

Cataloged
Indicator1 indicator cataloged

Types: onion.

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

shadowCanonical Name

Loading CVEs, techniques, indicators, malware, victims, and activity...