ShinyHunters, also referred to in some reporting as SCATTERED LAPSUS$, is a financially motivated cybercriminal and extortion actor associated with public release of exploit code and follow-on extortion activity. The actor has been linked to Oracle E-Business Suite exploitation activity in 2025, including publication of an exploit bundle and an extortion campaign that increased the likelihood of opportunistic compromise by other actors. Reporting ties this activity to exploitation of Oracle E-Business Suite flaws affecting internet-exposed enterprise applications, including attack chains involving Oracle Configurator and other E-Business Suite components. The group’s observed behavior includes releasing exploit material through public channels, enabling broader abuse beyond the original operators. In the Oracle E-Business Suite campaigns, the actor was associated with exploit publication on Telegram and with extortion activity directed at affected organizations. Available evidence supports capabilities in initial access via exploitation of public-facing applications, post-exploitation, exfiltration, and extortion-related operations. The actor’s public leak of exploit code also demonstrates a role in lowering barriers for secondary exploitation by other threat actors. Aliases in available reporting include SCATTERED LAPSUS$ and ShinyHunters. The naming overlap suggests either the same collective or a closely associated branding variant in the context of Oracle E-Business Suite exploitation and extortion activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Secondary threat actor that publicly released exploit code for Oracle E-Business Suite exploitation, increasing risk from opportunistic attackers.
Referenced as an extortion group associated with the leaked Oracle exploit that was blocked by the CVE-2025-61884 update.
SCATTERED LAPSUS$ is a threat actor collective known for publicly releasing exploit bundles and engaging in extortion campaigns. In this incident, they released exploit code for CVE-2025-61882 and conducted extortion against Oracle E-Business Suite customers.
Referenced in connection with Ivanti Virtual Traffic Manager activity and related detection content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.