ShinySp1d3r
ShinySp1d3r is an in-development ransomware and ransomware-as-a-service (RaaS) platform associated with the Scattered LAPSUS$ Hunters / SLSH ecosystem, with reporting linking its operators to ShinyHunters, Scattered Spider, and LAPSUS$. Public reporting states the malware has appeared in the wild and that the operation was announced in late 2025 as a joint effort intended to rival established ransomware groups such as LockBit and DragonForce. Multiple sources describe it as a custom ransomware family, with some reporting that SLSH members had previously relied on third-party encryptors including ALPHV/BlackCat, Qilin, RansomHub, and DragonForce before promoting ShinySp1d3r as their own service.
High-confidence reporting indicates the ransomware currently works on Windows, with operators claiming Linux and ESXi versions were planned or close to release. Reported capabilities include file encryption; ETW event log suppression; termination of processes and services to facilitate encryption; overwriting free disk space with random data; encryption of open network shares; and propagation or remote deployment via service creation, deployViaSCM, deployViaWMI, attemptGPODeployment, and startup script generation. One report states the malware is a modified version of HellCat ransomware enhanced with AI tools, but attribution of that claim comes from operator statements and should be treated cautiously.
The malware is consistently tied in reporting to financially motivated extortion activity by SLSH and related branding such as Scattered LAPSUS$ Hunters. The surrounding threat activity includes insider recruitment, social engineering, voice phishing, cloud/SaaS compromise, and data theft/extortion campaigns, including Salesforce-related supply-chain intrusions involving Gainsight and Salesloft Drift. Reporting also links the broader alliance to targeting large enterprises, including telecommunications, software, gaming, retail, hospitality, cloud/hosting, and call-center/BPO environments, with some sources noting focus on organizations with annual revenue above $500 million.
Known observables directly mentioned in the content include the user-agent string "Salesforce-Multi-Org-Fetcher/1.0" and IP address 3.239.45.43, both associated with related SLSH/Gainsight unauthorized-access activity rather than the encryptor itself. Overall, ShinySp1d3r is best characterized as an emerging Windows ransomware family and RaaS offering linked to the SLSH criminal alliance, combining encryption capability with the group’s established data-theft and extortion operations.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The criminals have been previewing a new ransomware-as-a-service operation called ShinySp1d3r, and a sample of their crypto-locking malware has appeared in the wild.
...a Telegram channel purportedly led by members of the ShinyHunters, Scattered Spider, and LAPSUS$ hacking groups, which touted the development of the ShinySp1d3r ransomware-as-a-service platform...
...a Telegram channel purportedly led by members of the ShinyHunters, Scattered Spider, and LAPSUS$ hacking groups, which touted the development of the ShinySp1d3r ransomware-as-a-service platform...
"In November 2025, SLSH publicly announced ShinySp1d3r — an in-development RaaS platform adding file encryption..."
Techniques & procedures
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
4 techniquesМожет распространяться путём взлома через незащищенную конфигурацию RDP
Может распространяться путём... вредоносной рекламы, веб-инжектов, фальшивых обновлений
Может распространяться путём... эксплойтов
Может распространяться путём... с помощью email-спама и вредоносных вложений
Persistence
1 techniqueImpact
2 techniquesRecent activity
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named ransomware family referenced in the content via a Unit 42 report title.
In-development RaaS platform attributed to SLSH, adding encryption to an existing data-extortion/social-engineering model; described with evasion, data destruction, and self-contained propagation, with Linux/ESXi versions in development.
A purported joint Ransomware-as-a-Service (RaaS) platform under development, intended to support intrusion and extortion operations.
ShinySp1d3r is a Ransomware-as-a-Service (RaaS) platform promoted by threat actors associated with ShinyHunters, Scattered Spider, and Lapsus$. It is designed to facilitate ransomware operations by providing tools and infrastructure to affiliates, focusing on acquiring privileged access through insider recruitment and initial access brokers.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.