Skip to main content
Mallory
Back to malware
MalwareRansomwareUsed by 4 actors

ShinySp1d3r

Also known asSh1nySp1d3r

ShinySp1d3r is an in-development ransomware and ransomware-as-a-service (RaaS) platform associated with the Scattered LAPSUS$ Hunters / SLSH ecosystem, with reporting linking its operators to ShinyHunters, Scattered Spider, and LAPSUS$. Public reporting states the malware has appeared in the wild and that the operation was announced in late 2025 as a joint effort intended to rival established ransomware groups such as LockBit and DragonForce. Multiple sources describe it as a custom ransomware family, with some reporting that SLSH members had previously relied on third-party encryptors including ALPHV/BlackCat, Qilin, RansomHub, and DragonForce before promoting ShinySp1d3r as their own service.

High-confidence reporting indicates the ransomware currently works on Windows, with operators claiming Linux and ESXi versions were planned or close to release. Reported capabilities include file encryption; ETW event log suppression; termination of processes and services to facilitate encryption; overwriting free disk space with random data; encryption of open network shares; and propagation or remote deployment via service creation, deployViaSCM, deployViaWMI, attemptGPODeployment, and startup script generation. One report states the malware is a modified version of HellCat ransomware enhanced with AI tools, but attribution of that claim comes from operator statements and should be treated cautiously.

The malware is consistently tied in reporting to financially motivated extortion activity by SLSH and related branding such as Scattered LAPSUS$ Hunters. The surrounding threat activity includes insider recruitment, social engineering, voice phishing, cloud/SaaS compromise, and data theft/extortion campaigns, including Salesforce-related supply-chain intrusions involving Gainsight and Salesloft Drift. Reporting also links the broader alliance to targeting large enterprises, including telecommunications, software, gaming, retail, hospitality, cloud/hosting, and call-center/BPO environments, with some sources noting focus on organizations with annual revenue above $500 million.

Known observables directly mentioned in the content include the user-agent string "Salesforce-Multi-Org-Fetcher/1.0" and IP address 3.239.45.43, both associated with related SLSH/Gainsight unauthorized-access activity rather than the encryptor itself. Overall, ShinySp1d3r is best characterized as an emerging Windows ransomware family and RaaS offering linked to the SLSH criminal alliance, combining encryption capability with the group’s established data-theft and extortion operations.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
ShinyHunters

The criminals have been previewing a new ransomware-as-a-service operation called ShinySp1d3r, and a sample of their crypto-locking malware has appeared in the wild.

via govinfosecuritygovinfosecurity.com
Scattered Spider

...a Telegram channel purportedly led by members of the ShinyHunters, Scattered Spider, and LAPSUS$ hacking groups, which touted the development of the ShinySp1d3r ransomware-as-a-service platform...

via scworldscworld.com
LAPSUS$

...a Telegram channel purportedly led by members of the ShinyHunters, Scattered Spider, and LAPSUS$ hacking groups, which touted the development of the ShinySp1d3r ransomware-as-a-service platform...

via scworldscworld.com
Scattered Lapsus$ Hunters

"In November 2025, SLSH publicly announced ShinySp1d3r — an in-development RaaS platform adding file encryption..."

via osint team blogosintteam.blog
MITRE ATT&CK

Techniques & procedures

6 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

4 techniques
T1133External Remote ServicesEvidence1

Может распространяться путём взлома через незащищенную конфигурацию RDP

T1189Drive-by CompromiseEvidence1

Может распространяться путём... вредоносной рекламы, веб-инжектов, фальшивых обновлений

T1190Exploit Public-Facing ApplicationEvidence1

Может распространяться путём... эксплойтов

T1566.001Spearphishing AttachmentEvidence1

Может распространяться путём... с помощью email-спама и вредоносных вложений

Persistence

1 technique
T1133External Remote ServicesEvidence1

Может распространяться путём взлома через незащищенную конфигурацию RDP

Impact

2 techniques
T1486Data Encrypted for ImpactEvidence5
TacticImpact

Unit 42. “New ShinySp1d3r Ransomware.”

T1657Financial TheftEvidence1
TacticImpact

часто публикуя украденные образцы на LimeWire, чтобы оказать давление на организации

ACTIVITY FEED

Recent activity

19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution4

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping6

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.