Shaoleaks is a ransomware operator no longer publishing new disclosures. Darkfield has indexed 4 public victims claimed by this operator between November 1, 2022. Shaoleaks is a relatively obscure ransomware group that emerged in November 2022, appearing to be financially motivated based on their operational patterns. The group's origin and potential affiliations remain unclear due to limited public reporting from major cybersecurity firms and law enforcement agencies. Available intelligence suggests the group employs standard ransomware deployment tactics, though specific details about their initial access vectors, encryption methods, or use of double extortion techniques have not been publicly documented by authoritative sources. The group has demonstrated a focused targeting approach, with documented attacks against media sector organizations, though the scale of their operations appears limited with only four known victims reported in open sources. Current intelligence indicates minimal ongoing activity from this group, with no recent high-profile incidents or law enforcement actions publicly reported, suggesting either dormancy, dissolution, or operations below the threshold of major security research attention.
How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.