Scattered LAPSUS$ Hunters (SLSH or SLH), also known as Trinity of Chaos, is a financially motivated cybercriminal collective and branding umbrella associated with overlapping participants and tradecraft from Scattered Spider, LAPSUS$, and ShinyHunters. It is not a single cohesive organization with a confirmed leadership structure. The collective is primarily associated with English-speaking, social-engineering-led data theft and extortion operations targeting enterprise SaaS environments and third-party service providers. SLSH-associated activity has relied on voice phishing and help-desk impersonation to steal single sign-on credentials and multi-factor authentication codes or sessions. Operators have used compromised identities to enroll attacker-controlled MFA devices, reset passwords, remove security notifications, access cloud identity providers, and pivot among connected SaaS applications. Reported operations include compromise of outsourced support personnel and third-party platforms, abuse of valid accounts and OAuth relationships, collection of data from customer-support and enterprise-cloud repositories, and bulk exfiltration through legitimate web services and APIs. The collective has also sought insider access, particularly within call centers, hosting providers, SaaS companies, telecommunications firms, and gaming organizations. Its principal monetization model is data-theft extortion: stealing sensitive corporate and customer data, demanding payment to prevent publication, and using leak sites and messaging channels to pressure victims. SLSH has advertised an encryption-less extortion-as-a-service model and operated a data leak site. Some activity and claims connected to the collective involve the purported development or use of ShinySp1d3r ransomware, but the relationship between that malware and the collective is not conclusively established. Public responsibility claims by SLSH are not independently reliable in all cases.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
44 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
Oracle released a security advisory addressing a critical, zero-day vulnerability impacting its E-Business Suite (EBS), identified during their investigation into the recently disclosed extortion campaign targeting EBS customers. CVE-2025-61882 (CVSS: 9.8) resides within the Oracle Concurrent Processing component's BI Publisher Integration in the EBS. It allows an unauthenticated attacker with network access via HTTP to potentially compromise the Concurrent Processing product.
CISA on Monday added CVE-2025-61884 to its Known Exploited Vulnerabilities (KEV) catalog, confirming its exploitation.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Coalition reportedly combining Scattered Spider's social-engineering initial access, ShinyHunters' data theft and publication, and LAPSUS$ media-pressure operations.
Mentioned as an example of a cybercriminal supergroup/overlapping association in a broader policy discussion about private offensive cyber operations.
Previously compromised enterprises and Salesforce organizations through access to connected third-party platforms, including Salesloft and Drift.
Referenced as a tradecraft comparison for shared phishing-kit infrastructure in a related vishing incident.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.