Threat Actor Characterization
You’re viewing the read-only version.
Sign in for analyst tools (editors, promote draft, file/relations management, etc.)
Scattered Lapsus$ Hunters
ID: 219b63c41bbabe87ef9f5bd451c19433
Cybercrime
Cybercriminal
Online Fraud Rings
Threat types: Extortion-as-a-Service, Social Engineering
Progress: 81%
Completeness: 73%
Freshness: 100%
Operation zone: —
Aliases
Limited alias preview
| Scattered Lapsus ShinyHunters | ScatteredLapsus$Hunters | S*** | — |
Showing 2 of 3 aliases in free preview.
Actor Network Graph
Open Network GraphMITRE ATT&CK®
confidence: medium-high
Scattered Lapsus$ Hunters (SLSH) is publicly reported as a cybercrime alliance blending tradecraft associated with Scattered Spider (UNC3944), LAPSUS$, and ShinyHunters. The most consistent operational model is identity-first compromise (vishing/help-desk manipulation and OAuth/SSO abuse), followed by SaaS tenant data theft (notably Salesforce customers) and coercive extortion pressure using leak-site deadlines and executive harassment/intimidation.
| Technique | Technique name | Tactics | Evidence |
|---|---|---|---|
| T1566 | Phishing | TA0001 |
|
| T1598 | Phishing for Information | TA0043 |
|
| T1078 | Valid Accounts | TA0001 TA0003 TA0004 TA0005 |
|
| T1528 | Steal Application Access Token | TA0006 |
|
| T1219 | Remote Access Tools | TA0011 |
|
| T1005 | Data from Local System | TA0009 |
|
| T1041 | Exfiltration Over C2 Channel | TA0010 |
|
| T1657 | Financial Theft | TA0040 |
|
| T1565 | Data Manipulation | TA0040 |
|
Scattered Lapsus$ Hunters - Cybercrime alliance / extortion ecosystem (EaaS-style data theft + harassment) with strong social-engineering tradecraft
Classification: Unclassified / Open Source Intelligence (OSINT) — TLP:WHITE
Executive brief
now
Saved successfully.
Hunting Playbook — Scattered Lapsus$ Hunters (SLSH)
Focus: Identity-first compromise (vishing/help desk), OAuth/SSO abuse, SaaS tenant data theft, and extortion pressure workflows. The goal is early detection before bulk export and coercion escalation.
Tip: Hover the section title to learn what’s included in Analyst / Premium plans.
Hunting Playbook
now
Saved successfully.
IOC Appendix
now
Saved successfully.
OSINT Library
now
Saved successfully.