Scattered LAPSUS$ Hunters is a loosely described hybrid cybercriminal grouping associated with public boasting on Telegram and positioned at the intersection of extortion-oriented cybercrime and online notoriety. The available reporting characterizes it as part of a broader trend in which actors blend criminal tradecraft, public influence behavior, and reputational coercion rather than operating as a conventional, formally structured ransomware brand. High-confidence detail on the group’s membership, origin, victimology, malware tooling, and sustained operational history is currently not available. Based on the available characterization, the group is associated with extortion-centric behavior and public-facing intimidation or self-promotion. The label suggests overlap with the ecosystem of actors inspired by or emulating LAPSUS$-style tactics, where social engineering, identity abuse, insider-style access, and rapid monetization or coercion may be more central than traditional encryption-led ransomware operations. However, specific campaigns, confirmed victims, and technical procedures attributable to this named group are not sufficiently established in the available facts to support more detailed attribution.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.