ShinySp1d3r, also styled Sh1nySp1d3r, is an emerging ransomware family and ransomware-as-a-service platform associated in public reporting with the Scattered LAPSUS$ Hunters (SLSH) cybercrime ecosystem, including operators linked to ShinyHunters, Scattered Spider, and LAPSUS$. Malicious samples were identified in late 2025 while the operation was reportedly still under development. The ransomware encrypts files and has been described as capable of encrypting VMware ESXi environments. Windows functionality has been reported, with Linux and additional ESXi support under development.
Reported functionality includes suppressing ETW event logging, terminating processes to facilitate encryption, overwriting free disk space with random data, discovering and encrypting accessible network shares, and propagating through service-control-manager, WMI, and Group Policy-based deployment mechanisms. It can also create startup scripts, providing a mechanism for continued execution. Samples contain references consistent with planned Tor-hosted leak-site infrastructure, indicating a prospective double-extortion model alongside encryption. The operation has been promoted as an affiliate service and is associated with broader SLSH activity involving data extortion, cloud and SaaS compromise, social engineering, and insider-access recruitment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
По данным EclecticIQ, параллельно идёт разработка RaaS-платформы shinysp1d3r для шифрования VMware ESXi.
On Oct. 4, 2025, the threat actors claimed to be developing a new form of ransomware named “SHINYSP1D3R” as noted in Figures 6 and 7.
...a Telegram channel purportedly led by members of the ShinyHunters, Scattered Spider, and LAPSUS$ hacking groups, which touted the development of the ShinySp1d3r ransomware-as-a-service platform...
...a Telegram channel purportedly led by members of the ShinyHunters, Scattered Spider, and LAPSUS$ hacking groups, which touted the development of the ShinySp1d3r ransomware-as-a-service platform...
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Unit 42 recently identified numerous malicious files while investigating a report on ShinySp1d3r ransomware, which is linked to the cybercrime group ShinyHunters.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Reported ransomware-as-a-service platform under development for encrypting VMware ESXi environments, potentially adding conventional file-encryption extortion to ShinyHunters' data-theft-and-extortion operations.
A named ransomware family referenced in the content via a Unit 42 report title.
In-development RaaS platform attributed to SLSH, adding encryption to an existing data-extortion/social-engineering model; described with evasion, data destruction, and self-contained propagation, with Linux/ESXi versions in development.
A purported joint Ransomware-as-a-Service (RaaS) platform under development, intended to support intrusion and extortion operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.