TAT25-84 is a threat cluster tracked by Dragos and also referred to as Scattered Lapsus Shiny Hunters. The group is associated with identity-centric intrusion activity affecting environments that host or connect to operational technology. Its tradecraft emphasizes abuse of enterprise identity and account-recovery processes rather than specialized OT exploitation, enabling compromise of systems that underpin industrial operations. Observed activity includes systematic exploitation of help-desk workflows, self-service password reset mechanisms, and multi-factor authentication enrollment processes to obtain privileged access. This indicates strong capability in initial access, credential theft, session and identity abuse, privilege escalation, and post-compromise operations against critical enterprise infrastructure linked to OT continuity. The group’s methods align with attacks that can evade detection until essential supporting systems such as virtualization, cloud services, backup platforms, or business systems become degraded or unavailable, indirectly disrupting industrial operations. TAT25-84 is notable as an example of attackers abusing identity controls to reach OT-adjacent assets without requiring bespoke industrial malware or direct manipulation of industrial protocols. High-confidence reporting supports the group’s use of social-engineering-adjacent workflow abuse and privileged account takeover, but does not establish ransomware deployment, destructive ICS manipulation, or a confirmed nation-state affiliation for this cluster.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.