Also known as: Scattered Lapsus$ Hunters, Scattered Spider, tracked as, hold it for ransom, UNC5936, Handala Hack Team, Void Manticore, Storm-0842, Dune, Red Sandstorm, Banished Kitten, Imperial Kitten, IMPERIAL KITTEN, Yellow Liderc, TA456, DUSTYCAVE, Crimson Sandstorm, Cuboid Sandstorm, Smoke Sandstorm, CURIUM, BOHRIUM, DEV-0228, SLSH, ShinyHunters, Shiny Hunters, Tortoiseshell, APT35, Newscaster Team, Magic Hound, G0059, Phosphorus, Mint Sandstorm, TunnelVision, COBALT MIRAGE, Agent Serpens, RICH ION
Scattered Lapsus$ Hunters emerged in August 2025 as an alliance of three prominent English‑speaking threat actor groups—Scattered Spider, LAPSUS$, and ShinyHunters. The coalition leverages each member’s specialty to stage coordinated extortion attacks that fuse sophisticated technical exploits with low‑friction social engineering. The group typically begins with validated credential abuse (email/password reuse, credential stuffing) or the theft of OAuth tokens through misconfigured SaaS integrations. They then elevate privileges by exploiting high‑value zero‑day vulnerabilities such as CVE‑2025‑61882 in Oracle E‑Business Suite, and misuse misconfigurations to access Salesforce tenants and AWS infrastructures. Inside the victim environment they deploy Java‑based loaders (e.g., GOLDVEIN.JAVA) followed by backdoors like BPFDoor or Klopatra, which provide persistence while silently exfiltrating large volumes of PII via Google Cloud Storage buckets, REST APIs, or self‑hosted GitLab repositories. The data exfiltration is routed to public Data Leak Sites (DLS), often hosted on domains previously used by BreachForums. The group then communicates ransom demands and leak notifications through Telegram channels, employing vishing campaigns to recruit insiders and disseminate victim datasets. Extortion pressure is amplified by posting screenshots, fabricated evidence, and strict payment deadlines. In some incidents they also use legitimate MDM tools such as the Intune Remote Wipe feature for destructive sabotage. Scattered Lapsus$ Hunters’ operations appear to be a single‑shot extortion model: after releasing stolen data on an DLS they claim no further information will be leaked, aiming to maximize immediate financial gain and reputational damage.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Scattered Lapsus$ Hunters is a financially‑driven coalition that combines members of Scattered Spider, LAPSUS$, and ShinyHunters to conduct extortion-as‑a‑service campaigns. They exploit zero‑day vulnerabilities, such as CVE‑2025‑61882 in Oracle EBS, harvest Salesforce tenant data, exfiltrate through cloud services, and publicly leak stolen records via a Data Leak Site to pressure victims into paying ransoms.
Goals & Targeting
The coalition’s strategic objective is rapid, high‑volume monetary extraction from a broad swath of sectors—ranging from finance and healthcare to aviation, defense, and entertainment—primarily targeting Israeli, Iranian, French, and Saudi organizations. By combining zero‑day exploitation with social engineering recruitment, they create a multi‑layer attack surface that forces victims into a sense of urgency, making them more willing to pay under tight deadlines.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Scattered Lapsus$ Hunters conducts rapid, multi‑sector extortion campaigns that typically unfold over a week: initial credential abuse leads to data breach, followed by the deployment of Java loaders and backdoors, silent exfiltration of millions of records, and public leaking via an DLS. Victims are contacted through Telegram channels with explicit deadlines, often forcing hurried payments. The coalition leverages social‑engineering to recruit insiders that facilitate credential theft and insider exfiltration, amplifying their reach across geographically dispersed enterprises.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available evidence from multiple independent security reports and intelligence feeds provides high confidence in the actor’s core capabilities, tactics, and extortion model. However, gaps remain regarding the precise operational hierarchy within the coalition, the full list of affiliated sub‑groups, and the long‑term sustainability of their single‑shot extortion approach.
No campaigns linked yet.
No observed data linked yet.
28
Techniques
65
Tools
0
Campaigns
19
IOCs
0
Observed Data
8
Tactics