Ransomware family
Scattered LAPSUS$ Hunters Ransomware Decryption & Data Recovery
- Active
- Critical
- No public decryptor
Scattered LAPSUS$ Hunters (SLSH) is a data-theft extortion alliance that formed on Telegram in August 2025 from ShinyHunters, Scattered Spider and LAPSUS$ members. It breaches Salesforce, Okta and Snowflake tenants at scale through vishing, insider recruitment and OAuth token abuse. Its own encryptor, ShinySp1d3r, was announced in November 2025 and samples have been analysed, but no deployment at scale has been confirmed as of September 2026.
- First seen
- 2025-08
- File extensions
- .[8位随机字符]
- Ransom notes
- R3ADME_[8位随机字符].txt
- Affected platforms
- Windows
Family profile
- File extensions
- .[8位随机字符]
- Ransom notes
- R3ADME_[8位随机字符].txt
- Contact patterns
- Telegram channels styled "scattered LAPSUS$ hunters part N" and "scattered LAPSUS$ hunters 4.0", used for naming victims and recruiting insiders
- Extortion mail from throwaway domains carrying a BTC address and a 72-hour countdown, with proof packs delivered over services such as LimeWire
- Victim-branded phishing domains shaped as `<company>sso`, `<company>okta`, `<company>internal`, `<company>support` plus a common TLD
- Tor (.onion) data leak site and per-victim negotiation pages
- ShinySp1d3r notes give only a Tox ID and a Case ID, with no mailbox
- Aliases / versions
- SLSH、SLH、Trinity of Chaos、ShinyHunters / Bling Libra(联盟核心品牌)、UNC6040 / UNC6240 / UNC6661 / UNC6671(Google 追踪编号)、ShinySp1d3r / ShinySpider(其 RaaS 加密器)
- First seen
- 2025-08
- Status
- Active
- Operational status
- Actively operating
- Threat level
- Critical
- Affected platforms
- Windows
- Tags
- Extortion-only
- Active
- Ransomware-as-a-Service
- Phishing
- Supply chain
In most incidents involving this group there is nothing to decrypt. Scattered LAPSUS$ Hunters is a data-theft extortion operation: voice phishing and OAuth token abuse get them into Salesforce, Okta, Microsoft 365 and Snowflake tenants, data is exported in bulk, and pressure is applied through a leak site, extortion mail and phone calls. Files are not renamed, systems keep running, and the entire loss sits on the confidentiality side.
Where encryption does occur, the payload is normally ShinySp1d3r, the encryptor the alliance announced in November 2025. No free decryptor exists: it is not listed on No More Ransom, and no vendor or law-enforcement key-recovery method has been published. Public reverse engineering notes that its ChaCha20 use omits Poly1305 authentication tags and that a dormant ML-KEM-768 routine is compiled in, but neither amounts to a usable decryption weakness.
A useful inverse test: if your files are encrypted and renamed while the extortionist claims to be SLSH, identify the sample before acting. Reporting through 2026 shows the brand is widely borrowed, and the payload may belong to an unrelated family. Re-run family identification instead of carrying over the assumptions on this page.
Be equally cautious with third parties offering to "delete the stolen data" or remove leak-site entries. Destruction cannot be verified technically, and such offers usually amount to paying the ransom and reselling it at a markup.
Latest activity
Bitdefender's September debrief: despite early-2026 announcements, no verified ShinySp1d3r deployments. In August the crew hit a healthcare org via Salesforce/Snowflake, claiming 200M+ records and demanding $55M.
SourcesGoogle and The Hacker News detail UNC6671 vishing: calls to employees' personal phones, AitM capture of credentials and MFA, then scripted bulk exfiltration from Microsoft 365 and Okta - tradecraft matching SLH.
SourcesUnit 42 notes ShinyHunters (Bling Libra) publicly distanced itself from the Scattered LAPSUS$ Hunters brand on 11 May 2026, though others keep using it; encryption now features in only 78% of extortion cases.
Sources
Overview
Scattered LAPSUS$ Hunters (SLSH, also SLH, dubbed the "Trinity of Chaos") surfaced on Telegram in August 2025, claiming members from ShinyHunters, Scattered Spider and LAPSUS$. It is a loose alliance inside The Com, not a single crew.
Its 2025 storyline runs through the Salesforce ecosystem: the August abuse of Salesloft Drift integration OAuth tokens, for which the alliance claimed credit on Telegram although that attribution remains disputed; a leak site launched on 3 October naming 39 companies and claiming close to a billion Salesforce records, which Salesforce publicly refused to pay for; and a November claim of roughly 285 further instances via Gainsight, alongside the ShinySp1d3r encryptor and open bidding for insider access. The actors put their victim count near 1,500 by mid-November 2025. Every one of these figures comes from the attackers and is not independently verified.
Through 2026 the alliance has grown looser. Google Threat Intelligence tracks functional clusters as UNC6040, UNC6240, UNC6661 and UNC6671 - a compartmentalised model where each stage sits with different participants - and a new ShinyHunters-branded leak site appeared in late January 2026. Claims that the crew had retired circulated mid-year, but the leak site and the extortion activity continued. Vendor reporting records an August 2026 healthcare incident in which the actors claimed over 200 million records exfiltrated in four days and demanded 55 million USD.
For Chinese enterprises the exposure is the multinational SaaS and identity estate, not the local file server. No public report documents a targeted campaign against mainland China organisations.
How to identify it
The first sign is usually notification, not broken files: extortion mail from an unfamiliar domain carrying a BTC address and a 72-hour countdown, a callout in a Telegram channel, a leak-site entry, or harassing calls to staff.
Identity and SaaS telemetry matters more than the endpoint:
- Unexpected MFA enrolments in Okta or Entra ID, with the "security method enrolled" notice silently deleted by a third-party OAuth app of the ToogleBox Recall type.
- Sign-ins concentrated on VPN and residential proxies such as Mullvad, Oxylabs and NetNut.
- Newly authorised connected apps in Salesforce, usually after an employee was walked through /setup/connect by phone.
- Keyword sweeps for proposal, internal, confidential or salesforce followed by bulk export, and PowerShell downloads from SharePoint or OneDrive.
If ShinySp1d3r was deployed: files gain an eight-character random extension (public samples show .XHuch5gq and .GcfVmSz3). The extension varies from file to file - public reverse engineering shows each build derives a fixed pool of candidate extensions and assigns them per file - so inconsistent extensions do not mean several families are present. Each directory gets a note named R3ADME_ plus a string from the same pool, the wallpaper is replaced, and the note supplies only a Tox ID and a Case ID.
Infection vectors
The alliance leans on people and tokens rather than on malware delivery:
- Voice phishing. Operators impersonate the IT help desk, often calling personal mobiles, scaling with AI voice platforms such as Vapi and Bland AI.
- Adversary-in-the-middle portals. Cloned Okta and SSO pages relay credentials and MFA codes live; the actor then enrols their own MFA device for durable access.
- Insider recruitment. Telegram channels openly bid for Okta, Microsoft SSO and Citrix access across credit bureaus, insurance, finance, retail and hospitality.
- Supply chain. OAuth tokens from third-party integrations (Salesloft Drift, Gainsight) are hijacked, and privileged engineering accounts on Git, BrowserStack and JFrog are targeted to reach CI/CD.
- SIM swapping and MFA fatigue, with exfiltration over MEGA, Google Drive and LimeWire.
Some reporting also lists exploitation of internet-facing identity middleware as an entry route, but that attribution lacks reviewable public evidence and should not reshape your priorities: the repeatedly confirmed entry points remain help-desk procedures and third-party integration tokens.
Once SaaS and identity access is obtained, they usually move straight to exfiltration and extortion rather than pivoting internally - which is why endpoint tooling often records nothing.
Encryption behavior
One misconception first: most incidents attributed to this group involve no encryption. Bitdefender's September 2026 debrief states that despite the early-2026 fanfare, encryptors have not featured in recent attacks, and that distributing credentials and stolen data remains the primary revenue stream.
What public analysis of the ShinySp1d3r encryptor shows (Windows build):
- ChaCha20 for file content, session keys wrapped with RSA-2048 (OAEP), no Poly1305 authentication tag.
- Files above 100 MiB are only partially encrypted via keystream seeking, so large databases and virtual disks may retain substantial untouched data.
- Recovery inhibition: shadow copies deleted, event logs cleared, thirty-plus processes killed (SQL Server included), optional free-space wiping.
- A note prefixed R3ADME_ per directory plus a wallpaper change; extensions vary per file and, like the note's random string, are drawn from a pool the build generates in advance.
- Lateral deployment via WMI, SCM, GPO, SMB or PsExec, off by default in analysed samples.
Public analysis covers Windows samples only. Vendors describe Linux and ESXi modules in development, the ESXi variant reportedly using AES-256, but as of September 2026 no public sample or real-world deployment has been verified, which is why this page lists Windows alone.
Assess before you act
Recoverability assessment
For data-theft extortion, recovery is not about decryption but about scoping the exposure accurately, meeting every notification duty and taking access back completely. We do not pay ransoms and do not negotiate on a client's behalf.
1) Establish what kind of incident this is. In most SLSH cases files are intact; where encryption did occur, determine whether the sample is ShinySp1d3r or another family borrowing the name.
2) Breach impact assessment - the core work. Reconstruct the objects, fields and row counts exported, from Okta System Log, Salesforce Event Monitoring, the Microsoft 365 unified audit log and Snowflake QUERY_HISTORY. Cross-check the proof pack, and never take the actors' record counts at face value - they are routinely inflated by counting rows rather than individuals. Retention is often only 30 to 90 days, so collect early.
3) Notification and compliance. Assess duties under China's PIPL, Data Security Law and the Network Data Security Management Regulations; cross-border operations must also weigh the GDPR 72-hour window. The attacker's countdown does not replace that process.
4) Credential and token rotation. Password resets alone are not enough. Remove attacker-enrolled MFA devices, revoke all OAuth and refresh tokens, terminate live sessions, withdraw suspicious connected apps, and rotate API keys and service-account secrets.
5) If ShinySp1d3r encryption is confirmed. There is no public decryptor. Assess backups and snapshots first; then partial-encryption repair, since files above 100 MiB often retain intact regions allowing page-level database extraction and virtual-disk repair; then unencrypted copies, log replay and carving. Exfiltrated data itself cannot be "recovered".
Our response plan
Hit by Scattered LAPSUS$ Hunters ransomware? What to do
Containment and preservation, identity and SaaS first
The scene is in the cloud, so cutting the LAN achieves nothing. Export and store offline the audit logs from Okta or Entra ID, Salesforce, Microsoft 365 and Snowflake immediately - most retain only 30 to 90 days. Flag suspicious sessions and tokens rather than mass-revoking straight away: preserve evidence before cleanup. In parallel, check for any endpoint footprint; if encrypted files or an R3ADME_ note appear, image the disks and capture memory on those hosts, do not reboot or power them off, and keep three to five encrypted samples plus the original note.
Family identification and authenticity check
Compare the sender domain, BTC address, Telegram channel name and leak-site entry to determine whether this is SLSH or ShinyHunters proper, an affiliated cluster, or someone borrowing the name - the brand was widely impersonated through 2026, and a misread sends the whole response the wrong way. Where a sample exists, confirm ShinySp1d3r from the extension shape (eight random characters), the note naming rule, and the ChaCha20 plus RSA-2048 implementation traits. Verify too that the proof pack really came from your systems; that check decides whether the threat is genuine.
Breach impact assessment
Reconstruct the actor's searches and exports line by line from platform audit logs, fixing the objects, fields, row counts and timeline, and separating personal information, sensitive personal information, trade secrets and regulated data such as PHI or cardholder data. Use your own logs to discount inflated claims. Deliver a written assessment: data categories and volumes affected, the population of individuals and customers involved, statutory notification recipients and deadlines, contractual notice duties, and any sign of continuing access. Every later decision rests on this document.
Access recovery and, where needed, data restoration
Work tokens first, passwords second: revoke every OAuth and refresh token, terminate live sessions, remove attacker-enrolled MFA devices, withdraw suspicious connected apps and integrations, rotate API keys and service-account secrets, restore tampered mailbox rules, then reset account passwords and move to phishing-resistant MFA. Support regulatory and customer notification. Where ShinySp1d3r encryption is confirmed, work only on images and copies with originals read-only, proceeding through backups and snapshots, partial-encryption repair of large files, log replay and carving, with integrity checks and business verification after each batch.
Attribution, hardening and handover
Reconstruct the full chain: which employee took the vishing call, what the phishing domain was, when the rogue MFA device was enrolled, whose integration token was hijacked, and the window in which exfiltration happened. Hardening concentrates on identity: help-desk verification procedures that forbid phone-only MFA resets, a move to phishing-resistant factors such as FIDO2, OAuth app governance with shortened token lifetimes, threshold alerting on bulk SaaS exports, lookalike-domain monitoring, and least-privilege plus four-eyes review on sensitive operations to blunt insider risk. Close with an incident report and a formal handover checklist.
Risk warning
What not to do
- Do not let the 72-hour countdown in the extortion mail set your pace, and do not open contact through the Telegram channel or Tox yourself - unilateral contact raises the price and hands the schedule to the attacker.
- Do not mass-reset passwords, delete suspicious OAuth apps or clear logs before forensics; those actions erase the only basis for scoping the exfiltration. Export and preserve first, clean up second.
- Do not accept the attacker's claim of hundreds of millions of records at face value; public analysis shows such counts are routinely inflated by counting rows, and notifying on their figures creates avoidable harm and legal exposure.
- Do not treat a password reset as the end of containment - unless refresh tokens, attacker-enrolled MFA devices and authorised third-party apps are cleared, the account is retaken immediately after the change.
- Do not pay because deletion was promised; destruction cannot be verified technically, and payment does not discharge statutory notification duties.
- Do not download or run any purported "ShinySp1d3r decryptor"; no free public decryptor exists, and such tools are usually secondary fraud or malware carriers.
Emergency response
Data already encrypted? Stop and let an engineer look first
We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.
Related scenarios
Domain Controller Compromise and Estate-Wide Encryption
A compromised domain controller hands the attacker a legitimate administrator identity, allowing an encryptor to be pushed to every host at once through Group Policy or remote execution. This page covers how such incidents present, the correct order for Active Directory recovery, and how to decide between cleanup and full rebuild.
ERP System Encrypted by Ransomware
An encrypted ERP is not a single broken database: the application tier, database, attachments and interfaces fail together, halting finance, procurement, production and inventory. This page covers the vulnerability entry points seen in Chinese ERP deployments, the order in which the four tiers are recovered, and how account sets are reconciled at sign-off.
ESXi / Hyper-V Virtualization Encrypted by Ransomware
Hypervisor-level encryption causes the widest blast radius of any ransomware event: dozens of production VMs go dark within an hour or two. This page covers what Linux ESXi encryptors actually do — shut down guests, encrypt vmdk, delete snapshots — the recovery value of flat disk files, and how Hyper-V and Proxmox cases differ.
Related industries
Financial Services Ransomware Response and Recovery
Financial and quasi-financial institutions face far stricter requirements on data integrity, transaction continuity and regulatory reporting than most sectors, so one ransomware event hits availability, customer trust and compliance simultaneously. This page covers the threat profile, a recovery approach centred on transactional consistency, and hardening priorities.
Healthcare Ransomware Response and Recovery
When a hospital is hit, registration, consultation, orders, billing, laboratory and imaging fail at the same moment and care falls back to paper. This page covers the healthcare threat picture, a recovery priority built around clinical continuity, and the handling of patient data and compliance obligations.
Retail and E-commerce Ransomware Response
In retail and e-commerce, ransomware translates directly into an inability to sell: order systems, membership, POS and warehouse fulfilment stop together and losses accrue by the hour. This page covers the sector's attack patterns, a recovery order built around the order-to-fulfilment chain, and handling of member data exposure.
Similar families
- No public decryptor
ShinyHunters
ShinyHunters (ShinyCorp, UNC6240, Bling Libra; MITRE ATT&CK G1057) has run data-theft extortion since 2019 without ever encrypting a file. Operators use voice phishing and stolen SaaS OAuth tokens to pull data out of Salesforce, Snowflake and Databricks, then press with a Tor leak site and a 72-hour bitcoin deadline. Victim postings continued through 2026.
- No public decryptor
Silent Ransom Group
Silent Ransom Group (Luna Moth, Chatty Spider, UNC3753) is a Conti-lineage crew that extorts without encrypting anything. Operators impersonate an internal IT helpdesk by phone, walk staff into a remote-access session, take documents out, then press with a clearnet leak site and calls to employees. The FBI flagged in-person intrusions with USB storage in both May 2025 and May 2026.
- No public decryptor
World Leaks
World Leaks is the extortion-only brand Hunters International adopted in January 2025: no encryptor, no renamed files, just data theft backed by a Tor leak site. No new victims have been posted since late July 2026 and the leak site has been unreachable, so the operation currently looks dormant.
FAQ
Scattered LAPSUS$ Hunters Frequently asked questions
Does Scattered LAPSUS$ Hunters encrypt files? If our files look normal, are we fine?
Usually not. The alliance's business is bulk data theft followed by extortion: files keep their names and systems keep running, so "our files still open" is not evidence that you are safe. What matters is the identity and SaaS side - unfamiliar MFA devices in Okta or Entra ID, newly authorised connected apps in Salesforce, abnormal bulk exports in the audit log. By the time the extortion mail arrives, the data has often been gone for weeks.
Can files with the eight-character random ShinySp1d3r extension be decrypted?
There is no free public decryptor. ShinySp1d3r encrypts content with ChaCha20 and wraps keys with RSA-2048, so without the operators' private key nothing can be reversed, and neither No More Ransom nor any vendor toolset lists it. Realistic routes are backups and snapshots; the intact regions that partial encryption leaves in files over 100 MiB, which allow page-level database extraction and virtual-disk repair at a ratio that depends on the pattern; unencrypted copies and log replay; and low-level carving. All of it requires stopping writes to the original volumes at once. Treat any "ShinySp1d3r decryptor" found online as untrustworthy.
We received extortion mail claiming to be SLSH - how do we tell if it is real?
Judge the evidence, not the wording. Ask for a verifiable sample, then go back to your own logs: do the objects, fields and timestamps match a real export? Can you find the corresponding session and queries in Okta, Salesforce, Microsoft 365 or Snowflake? Since 2026 the SLSH brand has been widely impersonated, and re-extortion using old breach data is common. Until that check is complete, do not acknowledge an incident publicly and do not start any settlement discussion.
If we pay, will the stolen data really be deleted?
It cannot be verified, and it is a poor basis for a decision. The operators still hold a copy that may be resold, reused by other members of the alliance, or recycled months later as a "new leak" - re-extortion has clear precedent in this ecosystem. Payment also does not discharge reporting and notification duties under China's PIPL and comparable regimes. We do not pay ransoms or negotiate; putting the same resources into impact assessment, credential rotation and compliance produces far more realistic returns.
What should we do in the first hour after a Salesforce or Okta compromise?
Four things. First, export and store the platform audit logs offline immediately - most retain only 30 to 90 days, and they are the only basis for sizing the loss. Second, lock the suspect accounts and sessions while checking for attacker-enrolled MFA devices and newly authorised connected apps, screenshotting before you change anything. Third, inventory third-party integrations and decide which OAuth tokens must be revoked. Fourth, bring in legal and compliance and start the notification-deadline assessment. We run 24/7 emergency response and can return an initial assessment and a prioritised action list within an hour of remote access.
Are Chinese enterprises likely to be targeted by this group?
No public report currently documents a targeted campaign against mainland China organisations, but the exposure is real. The alliance attacks multinational SaaS and identity tenants, so group headquarters, overseas subsidiaries and cross-border business lines running Salesforce, Okta, Microsoft 365 or Snowflake all sit within reach. Its entry points are help-desk procedures and employees' personal phones, neither of which is bounded by geography. Concentrate on phishing-resistant MFA, strict help-desk identity verification, and governance of third-party integration tokens.
Sources
- The Golden Scale: 'Tis the Season for Unwanted Gifts (Scattered LAPSUS$ Hunters, ShinySp1d3r RaaS) — Unit 42
- Bitdefender Threat Debrief, September 2026: The ShinyHunters Playbook — Widespread Extortion without Encryption
- Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft (UNC6040 / UNC6240 / UNC6661 / UNC6671) — Google Threat Intelligence
- ShinyHunters threat group profile (ShinySp1d3r encryption, SLSH alliance) — Halcyon
- ShinySp1d3r ransomware: extension, R3ADME note and removal guide — PCrisk
- ShinySp1d3r (ShinySpider) group profile and leak-site record — ransomware.live
- shinysp1d3r-intel: reverse engineering and detection content for ShinySp1d3r — GitHub
External links are provided for reference only. The content is published by third parties and does not represent our position.
Updated