Sp1d3r Hunters is a label used for a purportedly combined cybercriminal entity associated with ShinyHunters and Scattered Spider activity. It has been discussed as a useful umbrella name where attribution between those clusters is blurred or overlapping. The actor is linked to large-scale extortion operations and has been cited alongside major ransomware and data-extortion groups as a significant contributor to the recent rise in extortion attacks. The group is associated with data-theft-driven extortion rather than clearly documented encryption operations in the available reporting. It has been connected to repeated extortion activity against large enterprises, including follow-on extortion attempts tied to previously compromised victims. Reporting also links the cluster to social-engineering-heavy intrusion tradecraft similar to that associated with Scattered Spider, while public discussion indicates operational overlap with ShinyHunters. Similar actors in this ecosystem have been noted for targeting large companies and abusing remote access pathways for initial access. Known associated names and overlapping identities include ShinyHunters, Scattered Spider, and UNC3944. The available information supports treating Sp1d3r Hunters as a cybercriminal extortion actor or umbrella designation rather than a confirmed nation-state group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a ransomware operation contributing to increased data extortion activity.
Proposed combined label for the perceived merger/overlap of ShinyHunters and Scattered Spider; not an established independent group in the text, but a named activity cluster concept for attribution purposes.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.