ShinySp1d3r
ShinySp1d3r is an in-development ransomware and ransomware-as-a-service (RaaS) platform associated with the Scattered LAPSUS$ Hunters (SLSH) collective, with reporting linking its operators to ShinyHunters, Scattered Spider, and LAPSUS$. Public reporting states the malware was announced in 2025 and that samples have appeared in the wild while development was still ongoing. Multiple sources describe it as a custom ransomware family intended to support SLSH’s own affiliate program and reduce reliance on third-party ransomware operations previously used by the group, including ALPHV/BlackCat, Qilin, RansomHub, and DragonForce.
Reported capabilities include file encryption on Windows, planned or observed development for Linux and VMware ESXi environments, and features designed to encrypt ESXi systems. Additional reported functionality includes ETW event log suppression, termination of processes to facilitate encryption, overwriting free disk space with random data, searching for and encrypting open network shares, and propagation or remote deployment via service creation and mechanisms described as deployViaSCM, deployViaWMI, attemptGPODeployment, startup script generation, and network-share propagation. Some reporting describes it as a modified version of HellCat ransomware enhanced with AI tools, but that attribution is based on actor-linked claims.
The malware is tied in reporting to the broader SLSH criminal ecosystem, which has been linked to data theft, extortion, insider recruitment, and social-engineering-heavy intrusions, including Salesforce-related campaigns and cloud-focused compromises. Reporting names the actor "Rey" as a promoter or administrator connected to the operation and states ShinySp1d3r was publicly announced through Telegram channels used by SLSH. High-confidence context from the provided content indicates the platform was still under active development in late 2025, initially worked on Windows, and was expected to expand to Linux and ESXi. No stable ransom note, file extension, or other malware-specific IOC set is directly provided in the content, but related reporting mentions the user agent string "Salesforce-Multi-Org-Fetcher/1.0" and IP address 3.239.45[.]43 in adjacent SLSH intrusion activity rather than as direct ShinySp1d3r malware indicators.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
EclecticIQ analysts observed that the ‘shinysp1d3r’ ransomware-as-a-service (RaaS) network is currently in development, with features designed to encrypt VMware ESXi environments.
On Oct. 4, 2025, the threat actors claimed to be developing a new form of ransomware named “SHINYSP1D3R” as noted in Figures 6 and 7.
...a Telegram channel purportedly led by members of the ShinyHunters, Scattered Spider, and LAPSUS$ hacking groups, which touted the development of the ShinySp1d3r ransomware-as-a-service platform...
...a Telegram channel purportedly led by members of the ShinyHunters, Scattered Spider, and LAPSUS$ hacking groups, which touted the development of the ShinySp1d3r ransomware-as-a-service platform...
Techniques & procedures
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
4 techniques
Initial Access
Persistence
1 technique
Persistence
Recent activity
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named ransomware family referenced in the content via a Unit 42 report title.
In-development RaaS platform attributed to SLSH, adding encryption to an existing data-extortion/social-engineering model; described with evasion, data destruction, and self-contained propagation, with Linux/ESXi versions in development.
A purported joint Ransomware-as-a-Service (RaaS) platform under development, intended to support intrusion and extortion operations.
ShinySp1d3r is a Ransomware-as-a-Service (RaaS) platform promoted by threat actors associated with ShinyHunters, Scattered Spider, and Lapsus$. It is designed to facilitate ransomware operations by providing tools and infrastructure to affiliates, focusing on acquiring privileged access through insider recruitment and initial access brokers.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.