ShinySp1d3r is a ransomware service and associated criminal grouping linked to the broader Scattered Lapsus$ Hunters (SLSH) ecosystem. It has been described as emerging from a collaborative milieu that includes elements associated with ShinyHunters, Scattered Spider, and LAPSUS$, and has also been tied to an individual alleged to have held an administrative role in the Hellcat ransomware group. Available reporting indicates that ShinySp1d3r was presented as SLSH’s own ransomware offering rather than as a distinct nation-state operation. The actor’s activity is associated with financially motivated cybercrime, including data theft and extortion. Reporting links the broader SLSH ecosystem to theft of corporate data, threats against major enterprises, insider recruitment efforts, and use of ransomware tooling from established criminal programs. The group has been associated with social-engineering-heavy intrusion tradecraft characteristic of the surrounding cluster, including credential-focused compromise and post-compromise monetization. Because the available evidence specifically frames ShinySp1d3r as a ransomware service announced within SLSH, attribution of a fully separate operational history remains limited. Known associations and aliases include ShinySp1d3r as the ransomware service name and SLSH as the broader grouping with which it is connected. The surrounding cluster has been described as combining elements of Scattered Spider, LAPSUS$, and ShinyHunters.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a collaborative supergroup composed of elements from multiple named threat groups.
ShinySp1d3r is a ransomware service allegedly launched by SLSH, based on the Hellcat ransomware codebase. It is used in extortion and data theft operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.