ShinySp1d3r, also spelled Sh1nySp1d3r, is a ransomware family and ransomware-as-a-service offering associated with Scattered LAPSUS$ Hunters, a cybercriminal collective involving operators linked to ShinyHunters, Scattered Spider, and LAPSUS$. Announced in 2025, it adds file-encryption capabilities to an ecosystem previously prominent in enterprise data theft and extortion. Windows encryptor samples were identified in November 2025, while development also encompasses encryption of VMware ESXi environments.
The ransomware can search for and encrypt accessible network shares and incorporates network-deployment mechanisms using Windows Service Control Manager, Windows Management Instrumentation, and Group Policy. Its encryptor includes service creation and startup-script generation functionality. It suppresses Event Tracing for Windows telemetry, terminates processes to facilitate encryption, and can overwrite free disk space with random data. These features combine file encryption with mechanisms for spreading execution across enterprise Windows environments and reducing defensive visibility. ShinySp1d3r is associated with an affiliate-based operating model intended to monetize compromised enterprise access through ransomware extortion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The collective has also announced an in-development build of a new Ransomware-as-a-Service (RaaS) platform called “ShinySp1d3r”, described as a collaboration involving members associated with ShinyHunters, Scattered Spider, and Lapsus$.
The collective has also announced an in-development build of a new Ransomware-as-a-Service (RaaS) platform called “ShinySp1d3r”, described as a collaboration involving members associated with ShinyHunters, Scattered Spider, and Lapsus$.
The collective has also announced an in-development build of a new Ransomware-as-a-Service (RaaS) platform called “ShinySp1d3r”, described as a collaboration involving members associated with ShinyHunters, Scattered Spider, and Lapsus$.
The collective has also announced an in-development build of a new Ransomware-as-a-Service (RaaS) platform called “ShinySp1d3r”, described as a collaboration involving members associated with ShinyHunters, Scattered Spider, and Lapsus$.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
“Scattered Spider obtained initial access before one of the aforementioned groups was observed using ransomware for encryption.”
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware-as-a-service offering linked to the Scattered LAPSUS$ Hunters brand.
A ransomware-as-a-service offering attributed in the content to ShinyHunters. No operational, encryption, victim, or payload details are provided.
Reported ransomware-as-a-service platform under development for encrypting VMware ESXi environments, potentially adding conventional file-encryption extortion to ShinyHunters' data-theft-and-extortion operations.
A named ransomware family referenced in the content via a Unit 42 report title.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.