Find notable cyber news and cases, enriched with sources, timelines, and signals.

Scattered LAPSUS$ Hunters shifts from borrowed encryptors to ShinySp1d3r RaaS

Threat Actor Meta
First reported
Last updated
Happening score
H score 20
1 unique sources, 1 articles

Summary

Hide ▲

Scattered LAPSUS$ Hunters (SLSH) has shifted from using other gangs’ encryptors to launching ShinySp1d3r, giving the group its own ransomware-as-a-service brand and greater control over extortion operations. The group is widely described as an amalgam of Scattered Spider, LAPSUS$, and ShinyHunters, so the move reflects a broader ecosystem consolidation rather than a single-ransomware pivot. The change can strengthen affiliate recruitment, monetization, and operational autonomy across a wider victim base.

Related Happenings

Vect and TeamPCP industrialize ransomware through a supply-chain credential-theft alliance

Threat Actor Meta
H score67 First: 03.07.2026 14:30 Last: 03.07.2026 14:30 Sources 1

About this happening: Vect and TeamPCP formed a new ransomware-as-a-service partnership that combines supply-chain credential theft with extortion, expanding the risk of follow-on attac...

The Gentlemen ransomware group’s 90/10 RaaS model and rapid victim growth

Threat Actor Meta
H score26 First: 10.06.2026 17:03 Last: 10.06.2026 17:03 Sources 1

About this happening: The Gentlemen ransomware group has become a high-volume RaaS operation, using a 90/10 affiliate split to attract operators and expand its reach. The group now ranks as...

Silent Ransom Group shifts from Conti-linked ransomware participation to standalone data-theft extortion

Threat Actor Meta
H score21 First: 07.06.2026 17:09 Last: 07.06.2026 17:09 Sources 1

About this happening: Silent Ransom Group (UNC3753) is a standalone data-theft extortion actor that has operated separately since 2022 after the Conti shutdown, using stolen data and le...

Silent Ransom Group US law firm IT impersonation campaign

Campaign
H score36 First: 29.05.2026 16:00 Last: 29.05.2026 16:00 Sources 1

About this happening: Silent Ransom Group (SRG), also tracked as UNC3753, Chatty Spider, and Luna Moth, is running a financially motivated data theft extortion campaign against do...

BlackCat campaign expands across multiple victims

Campaign
H score39 First: 22.04.2026 14:00 Last: 22.04.2026 14:00 Sources 1

About this happening: The BlackCat ransomware operation ran a multi-victim extortion campaign against US organizations between April and November 2023, creating sustained ransom pressur...

Latest development: 01.05.2026 14:30

Ryan Goldberg and Kevin Martin were each sentenced to four years in prison for helping the BlackCat/ALPHV ransomware gang conduct attacks against multiple U.S. organizations during 2023. Prosecutors said the pair worked alongside Angelo Martino, paid BlackCat administrators a 20% share of ransom payments, and in one case received a Bitcoin ransom worth $1.2m while also leaking patient data from a healthcare victim.

Timeline

  1. 26.11.2025 19:22 2 articles · 7mo ago

    Scattered LAPSUS$ Hunters launches ShinySp1d3r ransomware-as-a-service

    Campaign Scope Update

    Scattered LAPSUS$ Hunters announced a new ransomware-as-a-service operation called ShinySp1d3r, marking a shift from its earlier pattern of using encryptors from other ransomware families such as ALPHV/BlackCat, Qilin, RansomHub, and DragonForce. The move gives the group a branded ransomware offering it can package, recruit around, and use for extortion operations.

    Show sources