Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Scattered Lapsus Hunters

Scattered Lapsus Hunters

APT35 TLP:CLEAR
Active

Also known as: Scattered Lapsus$ Hunters, Scattered Spider, tracked as, hold it for ransom, UNC5936, Handala Hack Team, Void Manticore, Storm-0842, Dune, Red Sandstorm, Banished Kitten, Imperial Kitten, IMPERIAL KITTEN, Yellow Liderc, TA456, DUSTYCAVE, Crimson Sandstorm, Cuboid Sandstorm, Smoke Sandstorm, CURIUM, BOHRIUM, DEV-0228, SLSH, ShinyHunters, Shiny Hunters, Tortoiseshell, APT35, Newscaster Team, Magic Hound, G0059, Phosphorus, Mint Sandstorm, TunnelVision, COBALT MIRAGE, Agent Serpens, RICH ION

Description

Scattered Lapsus$ Hunters emerged in August 2025 as an alliance of three prominent English‑speaking threat actor groups—Scattered Spider, LAPSUS$, and ShinyHunters. The coalition leverages each member’s specialty to stage coordinated extortion attacks that fuse sophisticated technical exploits with low‑friction social engineering. The group typically begins with validated credential abuse (email/password reuse, credential stuffing) or the theft of OAuth tokens through misconfigured SaaS integrations. They then elevate privileges by exploiting high‑value zero‑day vulnerabilities such as CVE‑2025‑61882 in Oracle E‑Business Suite, and misuse misconfigurations to access Salesforce tenants and AWS infrastructures. Inside the victim environment they deploy Java‑based loaders (e.g., GOLDVEIN.JAVA) followed by backdoors like BPFDoor or Klopatra, which provide persistence while silently exfiltrating large volumes of PII via Google Cloud Storage buckets, REST APIs, or self‑hosted GitLab repositories. The data exfiltration is routed to public Data Leak Sites (DLS), often hosted on domains previously used by BreachForums. The group then communicates ransom demands and leak notifications through Telegram channels, employing vishing campaigns to recruit insiders and disseminate victim datasets. Extortion pressure is amplified by posting screenshots, fabricated evidence, and strict payment deadlines. In some incidents they also use legitimate MDM tools such as the Intune Remote Wipe feature for destructive sabotage. Scattered Lapsus$ Hunters’ operations appear to be a single‑shot extortion model: after releasing stolen data on an DLS they claim no further information will be leaked, aiming to maximize immediate financial gain and reputational damage.

Goals & Targeting

Targeted Sectors

Retail
Hospitality
Healthcare
Financial services
Transportation
Aviation
Government
Telecommunications
Information technology
Entertainment
Defense
Media
Gaming
Legal services
Energy
Critical infrastructure
Pharmaceutical
Non profit
Education

Targeted Countries / Regions

IL
IR
FR
SA

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 21 hours ago

Executive Summary

Scattered Lapsus$ Hunters is a financially‑driven coalition that combines members of Scattered Spider, LAPSUS$, and ShinyHunters to conduct extortion-as‑a‑service campaigns. They exploit zero‑day vulnerabilities, such as CVE‑2025‑61882 in Oracle EBS, harvest Salesforce tenant data, exfiltrate through cloud services, and publicly leak stolen records via a Data Leak Site to pressure victims into paying ransoms.

Goals & Targeting

The coalition’s strategic objective is rapid, high‑volume monetary extraction from a broad swath of sectors—ranging from finance and healthcare to aviation, defense, and entertainment—primarily targeting Israeli, Iranian, French, and Saudi organizations. By combining zero‑day exploitation with social engineering recruitment, they create a multi‑layer attack surface that forces victims into a sense of urgency, making them more willing to pay under tight deadlines.

Enhanced Description

Key Capabilities

  • Zero‑day exploitation of enterprise apps (e.g., CVE‑2025‑61882 in Oracle EBS), Salesforce tenant data theft via OAuth token compromise, AWS cloud exfiltration using supply‑chain breaches, in‑memory Java loaders (GOLDVEIN.JAVA), backdoors like BPFDoor and Klopatra, public Data Leak Sites hosting stolen PII, extortion messaging through Telegram channels, credential reuse & phishing/spearphishing links, insider recruitment via vishing and social media
  • Data exfiltration over web services, cloud storage buckets, and GitLab repositories
  • Privilege escalation through misconfigured SaaS integrations
  • Social‑engineering recruitment of call‑center agents and platform employees

MITRE ATT&CK Tactics

Initial Access
Execution
Privilege Escalation
Defense Evasion
Exfiltration
Impact

ATT&CK Techniques

T1190 Exploit Public-Facing Application
T1203 Exploitation for Client Execution
T1041 Exfiltration Over Command & Control Channel
T1055.001 Process Injection
T1078 Valid Accounts
T1090 Connection Proxy
T1555.001 Credentials from Password Stores
T1528 Steal Application Access Token
T1589 Gather Victim Identity Information
T1566 Phishing
T1566.002 Spearphishing Link
T1592 Gather Victim Host Information
T1595 Active Scanning
T1567 Exfiltration Over Web Service
T1213 Data from Information Repositories

Software / Tooling

GOLDVEIN.JAVA
BPFDoor
Klopatra
TruffleHog
Evilginx2
Mimikatz
Infostealer SHA.exe
Cl0p Ransomware (for destructive sabotage)

Campaigns & Victims

Scattered Lapsus$ Hunters conducts rapid, multi‑sector extortion campaigns that typically unfold over a week: initial credential abuse leads to data breach, followed by the deployment of Java loaders and backdoors, silent exfiltration of millions of records, and public leaking via an DLS. Victims are contacted through Telegram channels with explicit deadlines, often forcing hurried payments. The coalition leverages social‑engineering to recruit insiders that facilitate credential theft and insider exfiltration, amplifying their reach across geographically dispersed enterprises.

IOC Patterns

  • Domain names including Data Leak Sites
  • Telegram channel identifiers
  • CVE vulnerability identifiers (e.g., CVE‑2025‑61882)
  • File names of backdoors and loaders (GOLDVEIN.JAVA, BPFDoor)
  • PII such as email addresses, phone numbers, dates of birth, frequent flyer details
  • Leak site URLs
  • Exfiltration IP addresses
  • Suspicious DNS queries

Recommended Actions

  • Patch all Oracle EBS installations to fix CVE‑2025‑61882 and any subsequent patches; maintain a rapid patch management cycle. "Implement" multi‑factor authentication on all SaaS accounts (Salesforce, AWS) and enforce strict OAuth token lifecycle controls. "Deploy" secret scanning tools such as TruffleHog in code repositories to detect leaked credentials or API keys. "Monitor" Salesforce and cloud environments for abnormal data flows, large outbound transfers, and suspicious OAuth token usage. "Block" known Data Leak Site domains and employ web filtering to prevent access. "Implement" robust incident response playbooks that include immediate containment of exfiltration channels and notification procedures. "Educate" employees on vishing and phishing campaigns, focusing on recognizing suspicious calls or messages about credential requests. "Utilize" threat intelligence feeds to detect active Telegram groups used by the coalition for coordination.

Suggested Tags

data‑exfiltration
zero‑day exploitation
oracle-ebs
salesforce-targeting
aws-targeting
telegram-communication
extortion
financial-gain
fin11-influence
oauth-supply-chain
Data Leak Site
PII leakage
scattered-lapsus-hunters

Confidence Assessment

The available evidence from multiple independent security reports and intelligence feeds provides high confidence in the actor’s core capabilities, tactics, and extortion model. However, gaps remain regarding the precise operational hierarchy within the coalition, the full list of affiliated sub‑groups, and the long‑term sustainability of their single‑shot extortion approach.

ATT&CK Techniques

Command & Control
1 technique
Stealth
1 technique
15 techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. https://www.picussecurity.com/resource/blog/scattered-lapsus-hunters-2025s-most-dangerous-cybercrime-supergroup — Cited by AI analysis.
  2. https://unit42.paloaltonetworks.com/scattered-lapsus-hunters/ — Cited by AI analysis.
  3. https://www.levelblue.com/blogs/spiderlabs-blog/scattered-lapsuss-hunters-anatomy-of-a-federated-cybercriminal-brand — Cited by AI analysis.
  4. https://industrialcyber.co/ransomware/scattered-lapsus-resurfaces-with-brokered-access-model-raising-risks-for-industrial-and-critical-infrastructure/ — Cited by AI analysis.
  5. https://falconfeeds.io/blogs/scattered-lapsus-hunters-investigative-timeline/ — Cited by AI analysis.
  6. https://www.dataminr.com/resources/intel-brief/slh-recruiting-women-for-operations — Cited by AI analysis.
  7. https://flare.io/learn/resources/chaotic-scattered-shiny-lapsus-spider — Cited by AI analysis.
  8. https://izoologic.com/web-app-security/threat-actor-profile-scattered-lapsus-hunter-5-0/ — Cited by AI analysis.
  9. https://socradar.io/blog/dark-web-profile-scattered-lapsus-hunters/ — Cited by AI analysis.
  10. https://en.wikipedia.org/wiki/ShinyHunters — Cited by AI analysis.
  11. https://flashpoint.io/blog/scattered-spider-threat-profile/ — Cited by AI analysis.
  12. https://www.halcyon.ai/threat-group/coinbasecartel — Cited by AI analysis.
  13. https://www.docontrol.io/blog/shinyhunters — Cited by AI analysis.
  14. https://www.dataminr.com/resources/blog/how-scattered-lapsus-hunters-illustrates-the-evolution-of-cybercrime/ — Cited by AI analysis.
  15. https://www.bankinfosecurity.com/blogs/whats-in-name-quest-to-understand-scattered-spider-p-4150 — Cited by AI analysis.
  16. https://www.rescana.com/post/resecurity-honeypot-incident-analysis-of-scattered-lapsus-hunters-claimed-breach-and-threat-intel — Cited by AI analysis.
  17. https://www.immersivelabs.com/resources/c7-blog/scattered-lapsus-hunters-the-cybercrime-group-redefining-threats — Cited by AI analysis.
  18. https://www.obsidiansecurity.com/blog/shinyhunters-and-scattered-spider-a-merger-of-chaos-in-the-2025-salesforce-attacks — Cited by AI analysis.
  19. https://medium.com/@ggabrielhd/threat-research-inside-scattered-lapsus-hunters-slh-unc6040-unc6395-4bab193c0899 — Cited by AI analysis.
  20. https://www.vectra.ai/modern-attack/threat-actors/scattered-spider — Cited by AI analysis.
  21. https://www.rescana.com/post/scattered-lapsus-hunters-launch-data-leak-site-targeting-salesforce-massive-oauth-supply-chain-bre — Cited by AI analysis.
  22. https://blog.eclecticiq.com/shinyhunters-calling-financially-motivated-data-extortion-group-targeting-enterprise-cloud-applications — Cited by AI analysis.
  23. https://redpiranha.net/news/threat-intelligence-report-september-30-october-6-2025 — Cited by AI analysis.
  24. https://www.vectra.ai/blog/cl0p-is-back-exploiting-supply-chains-again — Cited by AI analysis.
  25. https://cloud.google.com/blog/topics/threat-intel/oracle-ebusiness-suite-zero-day-exploitation — Cited by AI analysis.
  26. https://www.security.com/threat-intelligence/ransomware-extortion-epidemic — Cited by AI analysis.
  27. https://pushsecurity.com/blog/stryker-handala-report — Cited by AI analysis.
  28. https://falconfeeds.io/blogs/compromised-insider-threat-compromised-accounts-masquerading-as-employees/ — Cited by AI analysis.
  29. https://iverify.io/blog/the-attack-surface-in-your-pocket-and-how-scattered-spider-socially-engineers-their-way-inside — Cited by AI analysis.
  30. https://www.darkowl.com/blog-content/threat-actor-spotlight-scattered-lapsus-hunters/ — Cited by AI analysis.
  31. https://www.facebook.com/theguardianaustralia/posts/hacker-collective-scattered-lapsus-hunters-demanded-payment-in-return-for-preven/1260214389473812/ — Cited by AI analysis.
  32. https://krebsonsecurity.com/2025/11/meet-rey-the-admin-of-scattered-lapsus-hunters/ — Cited by AI analysis.
  33. https://unit42.paloaltonetworks.com/scattered-lapsus-hunters-updates/ — Cited by AI analysis.
  34. https://www.vectra.ai/blog/scattered-lapsus-hunters-announce-they-are-going-dark-but-the-threat-remains — Cited by AI analysis.
  35. https://sosransomware.com/en/ransomware-groups/scattered-lapsus-hunters-the-cybercrime-alliance-that-will-shake-global-businesses-in-2025/ — Cited by AI analysis.
  36. https://www.halcyon.ai/threat-group/scatteredspider — Cited by AI analysis.
  37. https://www.dataminr.com/resources/intel-brief/slh-recruiting-women-for-vishing/ — Cited by AI analysis.
  38. https://reliaquest.com/blog/zendesk-scattered-lapsus-hunters-latest-target/ — Cited by AI analysis.
  39. https://www.bleepingcomputer.com/news/security/hackers-claim-resecurity-hack-firm-says-it-was-a-honeypot/amp/ — Cited by AI analysis.
  40. https://hackread.com/shinyhunters-breach-us-cybersecurity-resecurity-firm/ — Cited by AI analysis.
  41. https://databreaches.net/ — Cited by AI analysis.
  42. https://www.theregister.com/2025/10/03/scattered_lapsus_hunters_latest_leak/ — Cited by AI analysis.
  43. https://www.bleepingcomputer.com/news/security/shinyhunters-starts-leaking-data-stolen-in-salesforce-attacks/ — Cited by AI analysis.
  44. https://techcrunch.com/2025/10/03/hacking-group-claims-theft-of-1-billion-records-from-salesforce-customer-databases/ — Cited by AI analysis.
  45. https://appomni.com/blog/saas-supply-chain-attacks-mitre-attck-mapping/ — Cited by AI analysis.
  46. https://attack.mitre.org/techniques/T1566/ — Cited by AI analysis.
  47. https://www.anomali.com/blog/salesloft-drift-breach-recap — Cited by AI analysis.
  48. cloud.google.com — Cited by web research for: UNC5936

Intel Summary

28

Techniques

65

Tools

0

Campaigns

19

IOCs

0

Observed Data

8

Tactics

Tags

Scattered LAPSUS Hunters
Vishing
Extortion
SaaS Targeting
ShinyHunters
Telegram
Spearphishing
Data Exfiltration
OAuth Supply Chain Attack
Zero-Day Exploit
Supply Chain Attack
Social Engineering
Insider Accounts
Cybercrime
Coalition
Ransomware
Backdoor
Cloud Misconfiguration
Credential Abuse
Oracle EBS
Salesforce
GitLab
Intune Remote Wipe
data‑exfiltration
zero‑day exploitation
oracle-ebs
salesforce-targeting
aws-targeting
telegram-communication
extortion
financial-gain
fin11-influence
oauth-supply-chain
Data Leak Site
PII leakage
scattered-lapsus-hunters

Details

MITRE ID
APT35
Type
Unknown
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
Iran (IR)
Confidence
60%
Added
Jul 27, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.