Ransomware Intelligence

scattered lapsus$ hunters

Ransomware group profile

48Victims
United StatesSource country
57Impact score
Also Known As
Scattered Lapsus$ Hunters
SLSH
Scattered Lapsus$ Hunters (SLH)

Description

ShinySp1d3r is a ransomware-as-a-service platform that emerged in mid-2025, developed by the Scattered LAPSUS$ Hunters collective. This group aims to achieve financial gain through custom-built ransomware, employing advanced social engineering tactics and a double extortion model to pressure victims into compliance.

Key insights

  • Utilizes a custom, Go-based ransomware encryptor leveraging ChaCha20 and RSA-2048 encryption methods.
  • Employs tactics such as vishing, SIM swapping, and insider recruitment for initial access.
  • Targets a diverse range of sectors including healthcare, education, and manufacturing.
  • Incorporates techniques to evade detection by manipulating logging processes and overwriting memory buffers.
  • Implements a double extortion strategy involving both data encryption and exfiltration.
  • Deploys across multiple platforms, including Windows, Linux, and VMware ESXi.

Threat Level & Status Breakdown

For scattered lapsus$ hunters · Based on incidents in selected period

2threat level
Aggressiveness5/ 10
Lethality0/ 10
Criticality0.8/ 10

Status Breakdown

Negotiating2.1%1
Claimed16.7%8
First seenOct 2025
Last seenOct 2025
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 2, 2026

Recent activity

Monthly attack count for scattered lapsus$ hunters in the selected period

48Total attacks
48peak in Oct
48avg / month
Oct015304560

Intelligence

IOCs, YARA/Sigma rules, and related families for scattered lapsus$ hunters

  1. 670a269d935f1586d4f0e5bed685d15a38e6fa790f763e6ed5c9fdd72dce3cf2
  2. 3bf53cddf7eb98d9cb94f9aa9f36c211a464e2c1b278f091d6026003050281de
  3. 62dc6ed7c83769648b5c59ad9cc2a4e26daec96a952eb44c93fd45f2011a3444
View full IOC feed3 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for scattered lapsus$ hunters

Other

T1486

T1486

T1490

T1490

T1078

T1078

T1562

T1562

T1059

T1059

T1021

T1021

T1021.001

T1021.001

T1547

T1547

T1080

T1080

T1047

T1047

T1489

T1489

T1203

T1203

Victims(48)

CompanyDomainCountryIndustryStatusDiscovered
Engie ResourcesEnergy & Utilities
Claimed
8 months ago
TelstraAU AustraliaTechnology
Claimed
8 months ago
S&P Globalspglobal.comUS United StatesTechnology
Claimed
8 months ago
CIC VietnamVN VietnamProfessional Services
Claimed
8 months ago
Red Hat, Inc.US United StatesTechnology
Claimed
8 months ago
PumaRetail & E-Commerce
Claimed
8 months ago
Albertsons (Jewel Osco, etc)US United StatesRetail & E-Commerce
Claimed
8 months ago
Toyota Motor CorporationsJP JapanManufacturing
Claimed
8 months ago
1-800AccountantFinancial Services
Unknown
8 months ago
IKEAUS United StatesRetail & E-Commerce
Unknown
8 months ago
ChanelRetail & E-Commerce
Unknown
8 months ago
TransUnionUS United StatesFinancial Services
Unknown
8 months ago
Pandorapandora.netDK DenmarkRetail & E-Commerce
Unknown
8 months ago
CiscoUS United StatesTechnology
Unknown
8 months ago
Google AdsenseUS United StatesTechnology
Unknown
8 months ago
Air France-KLMFR FranceTransportation
Unknown
8 months ago
SaksfifthUS United StatesRetail & E-Commerce
Unknown
8 months ago
CarMaxUS United StatesRetail & E-Commerce
Unknown
8 months ago
Qantas Airways LimitedAU AustraliaHospitality
Unknown
8 months ago
TripleAaaa.comUS United StatesHospitality
Unknown
8 months ago

Page 1 of 3