Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to malware
MalwareRansomwareUsed by 4 actors

ShinySp1d3r

Also known asSh1nySp1d3r

ShinySp1d3r is an in-development ransomware and ransomware-as-a-service (RaaS) platform associated with the Scattered LAPSUS$ Hunters (SLSH) collective, with reporting linking its operators to ShinyHunters, Scattered Spider, and LAPSUS$. Public reporting states the malware was announced in 2025 and that samples have appeared in the wild while development was still ongoing. Multiple sources describe it as a custom ransomware family intended to support SLSH’s own affiliate program and reduce reliance on third-party ransomware operations previously used by the group, including ALPHV/BlackCat, Qilin, RansomHub, and DragonForce.

Reported capabilities include file encryption on Windows, planned or observed development for Linux and VMware ESXi environments, and features designed to encrypt ESXi systems. Additional reported functionality includes ETW event log suppression, termination of processes to facilitate encryption, overwriting free disk space with random data, searching for and encrypting open network shares, and propagation or remote deployment via service creation and mechanisms described as deployViaSCM, deployViaWMI, attemptGPODeployment, startup script generation, and network-share propagation. Some reporting describes it as a modified version of HellCat ransomware enhanced with AI tools, but that attribution is based on actor-linked claims.

The malware is tied in reporting to the broader SLSH criminal ecosystem, which has been linked to data theft, extortion, insider recruitment, and social-engineering-heavy intrusions, including Salesforce-related campaigns and cloud-focused compromises. Reporting names the actor "Rey" as a promoter or administrator connected to the operation and states ShinySp1d3r was publicly announced through Telegram channels used by SLSH. High-confidence context from the provided content indicates the platform was still under active development in late 2025, initially worked on Windows, and was expected to expand to Linux and ESXi. No stable ransom note, file extension, or other malware-specific IOC set is directly provided in the content, but related reporting mentions the user agent string "Salesforce-Multi-Org-Fetcher/1.0" and IP address 3.239.45[.]43 in adjacent SLSH intrusion activity rather than as direct ShinySp1d3r malware indicators.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
ShinyHunters

EclecticIQ analysts observed that the ‘shinysp1d3r’ ransomware-as-a-service (RaaS) network is currently in development, with features designed to encrypt VMware ESXi environments.

via eclecticiq blogblog.eclecticiq.com
Scattered Lapsus$ Hunters

On Oct. 4, 2025, the threat actors claimed to be developing a new form of ransomware named “SHINYSP1D3R” as noted in Figures 6 and 7.

via palo alto networks unit 42 blogunit42.paloaltonetworks.com
Scattered Spider

...a Telegram channel purportedly led by members of the ShinyHunters, Scattered Spider, and LAPSUS$ hacking groups, which touted the development of the ShinySp1d3r ransomware-as-a-service platform...

via scworldscworld.com
LAPSUS$

...a Telegram channel purportedly led by members of the ShinyHunters, Scattered Spider, and LAPSUS$ hacking groups, which touted the development of the ShinySp1d3r ransomware-as-a-service platform...

via scworldscworld.com
MITRE ATT&CK

Techniques & procedures

6 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

4 techniques
T1133External Remote ServicesEvidence1

Может распространяться путём взлома через незащищенную конфигурацию RDP

T1189Drive-by CompromiseEvidence1

Может распространяться путём... вредоносной рекламы, веб-инжектов, фальшивых обновлений

T1190Exploit Public-Facing ApplicationEvidence1

Может распространяться путём... эксплойтов

T1566.001Spearphishing AttachmentEvidence1

Может распространяться путём... с помощью email-спама и вредоносных вложений

Persistence

1 technique
T1133External Remote ServicesEvidence1

Может распространяться путём взлома через незащищенную конфигурацию RDP

Impact

2 techniques
T1486Data Encrypted for ImpactEvidence6

EclecticIQ analysts observed that the ‘shinysp1d3r’ ransomware-as-a-service (RaaS) network is currently in development, with features designed to encrypt VMware ESXi environments.

T1657Financial TheftEvidence1

часто публикуя украденные образцы на LimeWire, чтобы оказать давление на организации

ACTIVITY FEED

Recent activity

21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution4

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping6

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.