Shady Squirrel is a Russian-speaking threat actor active since at least July 2023, controlling over 700 domains. It sends fraudulent traffic to initial access brokers and cybercriminals like SocGholish, as well as to tech support scams and affiliate marketing networks using Keitaro servers.