Uptime Hamster: 10d 10h 56mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza SHADOW-VOID-042

SHADOW-VOID-042

0 incidentes 0 paises 0 sectores apt RU Ultimo: -
Ver en IntelTracker → APTTrail →
SHADOW-VOID-042 emerged in October 2025 as a temporary intrusion set, identified through spear-phishing campaigns that demonstrated significant technical overlap with Void Rabisu, a threat actor aligned with Russian interests. While Void Rabisu evolved from financially motivated cybercrime, originally linked to the Cuba ransomware, into a primary espionage threat actor, SHADOW-VOID-042's observed activities are focused on intelligence collection rather than direct ransomware deployment. This group specifically distinguishes itself by its highly targeted approach, employing tailored spear-phishing lures such as fake software updates and HR-related documents, and notably compromised cybersecurity vendors, including a Trend Micro subsidiary, by impersonating their legitimate updates. The group is currently tracked separately from Void Rabisu due to the absence of a definitive link to the ROMCOM backdoor in observed SHADOW-VOID-042 campaigns and a lack of confirmed Ukraine-specific targeti

Actores similares

shadowbyt3actor · 13blackshadowransomware · 2shadowactor · 2shadowbyt3sactor · 2apolloshadowactor · 1shadowbyt3$actor · 1ShadowByt3$ransomware · 1void-balauractor · 1Void Blizzardapt · 0Void Arachneapt · 0
Tipo
apt
Pais origen
RU
Motivacion
-
Impacto
1
Actualizado
Sat, 07 Fe

Sectores objetivo (SOCRadar)

Computer Systems Design and Related Services