Also known as: CryptoChameleon, Octo Tempest, UNC3944, tracked as, hold it for ransom, Scattered Spider, SLSH, ShinyHunters
Crimson Collective has positioned itself as a sophisticated threat actor that exploits misconfigurations in cloud environments, especially AWS, to gain long‑term persistence. They routinely search for exposed IAM keys with TruffleHog, create new users or elevate privileges by attaching permissive policies, and then pivot into higher‑value assets such as RDS databases. By leveraging native AWS services—exposing RDS snapshots to S3 buckets, using Amazon Simple Email Service (SES) to deliver extortion notes, and exploiting WinRM endpoints—they can exfiltrate data and conduct ransomware campaigns with minimal detectability. The group also demonstrates a broader attack surface by deploying AI‑powered phishing pages via Softr against Microsoft Exchange/OWA, targeting Cisco products in CVE‑2025‑20393 and CVE‑2023‑20198, and using a mix of public‑facing exploits (e.g., drive‑by compromises) and legitimate tools like PsExec, anyDesk, and mshta. Crimson Collective’s campaigns are highly lucrative: they target finance, healthcare, retail, defense and other strategic sectors in the U.S., France, and Japan. They frequently leverage high‑profile corporate accounts to extort victims for cash or cryptocurrency while quietly exfiltrating sensitive data through cloud channels.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Crimson Collective is a financially driven cyber‑criminal group that leverages cloud infrastructures—particularly AWS—for data exfiltration and extortion. In September 2025 they announced a massive breach of Red Hat’s private GitHub repositories, claiming 570 GB and dozens of customer engagement reports. Their tactics combine credential theft, privilege escalation, and the use of native cloud services to stealthily move laterally and exfiltrate data while demanding ransoms via Amazon SES.
Goals & Targeting
The actor’s primary objective is monetary gain via a hybrid model of ransomware and data‐theft‑extortion. By compromising long‑term IAM credentials they can establish persistent, high‑privilege access to target AWS environments where they identify valuable data stored in RDS, S3, or other services. Target selection focuses on large enterprises with complex cloud footprints—particularly those operating in finance, healthcare, retail and defense sectors across the U.S., France and Japan—to maximize payout potential while minimizing exposure and increasing the likelihood of a profitable ransom negotiation.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Crimson Collective operates on a repeatable framework that capitalizes on cloud misconfigurations and public‑facing services. Campaigns are typically initiated with credential discovery using TruffleHog, followed by stealthy lateral movement within AWS and the exploitation of exposed management interfaces such as WinRM and WorkMail. Data harvesting is performed via native snapshot exports to S3, and exfiltration is complemented by malicious web service usage (SNS/SSE) or direct transfer to staging buckets. The group has demonstrated repeat attacks against Red Hat’s customers and is suspected to maintain a partnership network that includes other ransomware labs for data‑theft‑extortion operations. Victims are mainly large enterprises in high‑value sectors across the U.S., France, and Japan, with an operational tempo of several weeks per engagement.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The evidence base for Crimson Collective’s activities is a mix of verified company statements, security vendor reports, and publicly disclosed CVEs. While multiple independent sources corroborate their use of cloud credential exploitation and extortion tactics, direct attribution to the group remains largely dependent on claim‑based disclosures (e.g., Red Hat’s notification). Key gaps persist around the full scale of compromised assets, successful ransom collections, and exact timelines across distinct incidents.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
43
Tools
0
Campaigns
26
IOCs
0
Observed Data
14
Tactics