Servicio criminal / operación underground

Scattered Lapsus$ Hunters

Scattered Lapsus$ Hunters (also described as Scattered Lapsus ShinyHunters, often abbreviated SLSH) is publicly reported as a cybercrime alliance that blends elements associated with three well-known clusters/brands: Scattered Spider (aka UNC3944 / Octo Tempest), LAPSUS$, and ShinyHunters. Reporting emphasizes that the alliance’s operational model is data theft + extortion pressure, frequently without the need for “classic” ransomware encryption. This aligns with an Extortion-as-a-Service (EaaS) posture: compromise, steal, threaten public exposure, and apply coercive pressure through harassment and intimidation of executives and families, while leveraging public visibility (journalists/regulators notifications) to accelerate victim compliance.

Multiple sources tie SLSH to large-scale intrusions into Salesforce customer tenants (victims are Salesforce customers, rather than Salesforce being “exploited”), achieved via social engineering (vishing) and OAuth/SSO abuse rather than platform vulnerabilities. A core theme across reporting is that SLSH should be modeled as a “The Com” ecosystem product: youth-linked, brand-fluid, and capable of rebranding and coalition shifts. This is a critical analytic lens: defenders should focus on behavioral tradecraft (help desk social engineering, token abuse, cloud tenant exploitation, executive harassment workflows) rather than expecting stable malware signatures.

Confidence: High that SLSH is a real, active alliance brand associated with social engineering-driven data theft extortion and a public-facing leak/pressure model (multiple reputable sources). Medium–High on specific named-member attribution in open reporting (some sources list handles; identity claims require caution). High that Salesforce campaigns are social-engineering driven (consensus across multiple sources). Medium on long-term “organizational coherence” (brand fluidity is a feature, not a bug).

Creado por iQBlack CTI Team
Colaboradores 1
Última actualización 2026-08-19

ATT&CK

MITRE ATT&CK

T1005Data from Local System
T1041Exfiltration Over C2 Channel
T1078Valid Accounts
T1219Remote Access Tools
T1528Steal Application Access Token
T1565Data Manipulation
T1566Phishing
T1598Phishing for Information
T1657Financial Theft

Research

OSINT seleccionado