Scattered Lapsus$ Hunters, also known as SLH, SLSH, Lapsus$ Hunters, and Trinity of Chaos, is a financially motivated cybercriminal umbrella collective combining members associated with Scattered Spider, LAPSUS$, and ShinyHunters. Its public branding emerged in August 2025, with Telegram channels used to coordinate threats and publicize impending data leaks. Membership and operational relationships are fluid rather than those of a single, fixed hierarchical organization. Rey, also known as Saif al-Din Khader, has been identified as a technical operator, administrator, and public representative. The collective targets large enterprises, particularly telecommunications providers, software and gaming companies, cloud and hosting providers, and call-center or business-process-outsourcing organizations. Its recruitment and access-purchasing activity prioritizes the United States, United Kingdom, Australia, Canada, and France, and organizations with annual revenue exceeding approximately $500 million. It recruits insiders and access brokers through commission-based arrangements, seeking directory-integrated systems, corporate identity-provider access, cloud administrative credentials, and remote-access services. Its operations emphasize social engineering, compromised identities, third-party SaaS access, data theft, and extortion through threatened disclosure. The collective has released exploit code targeting Oracle E-Business Suite vulnerability CVE-2025-61882 and a SAP NetWeaver chain involving CVE-2025-31324 and CVE-2025-42999. It has also announced an in-development ransomware-as-a-service platform called ShinySp1d3r. That announcement does not establish operational deployment of the platform. Attribution requires particular care because associated crews retain separate identities and impersonator accounts have circulated older breach material under the collective's branding.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
The origins of the hostility trace to autumn 2025 during an extortion campaign centered on an Oracle E-Business Suite (EBS) zero-day vulnerability designated as CVE-2025-61882. Threat intelligence tracking revealed that unpatched enterprise Oracle EBS instances were systematically targeted to exfiltrate critical corporate databases from over one hundred corporations.
This maximum severity unrestricted file upload vulnerability allowed attackers to deploy JSP web shells and execute commands remotely via simple HTTP requests, making it accessible even to attackers with limited technical expertise.
CISA on Monday added CVE-2025-61884 to its Known Exploited Vulnerabilities (KEV) catalog, confirming its exploitation.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Described as an amalgamation of Scattered Spider, LAPSUS$, and ShinyHunters. Brian Krebs identified the reportedly arrested Saif al-Din Khader, nicknamed Rey, as its technical operator and public face. The article does not separately attribute specific attacks or malware to this combined cluster.
Described by Brian Krebs as an amalgamation of Scattered Spider, LAPSUS$, and ShinyHunters. Reportedly arrested ShinyHunters member Saif al-Din Khader, known as Rey, was identified as its technical operator and public face. No separate campaign or technical activity is attributed to the combined group in the article.
The group is attributed with the late-August 2025 Jaguar Land Rover breach, which disrupted IT systems, halted manufacturing, affected dealer systems and supplier orders, and involved theft of personal payroll data belonging to thousands of employees. Brian Krebs described Khader, an arrested suspected ShinyHunters member known as Rey, as this group's technical operator and public face.
An umbrella hacking group that includes ShinyHunters. The article connects the detained suspect, Saif al-Din Khader, to this broader organization through prior reporting.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.