{"id":6071,"date":"2025-08-12T10:03:35","date_gmt":"2025-08-12T10:03:35","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/08\/12\/scattered-spider-with-new-telegram-channel-list-organizations-it-attacked\/"},"modified":"2025-08-12T10:03:35","modified_gmt":"2025-08-12T10:03:35","slug":"scattered-spider-with-new-telegram-channel-list-organizations-it-attacked","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/08\/12\/scattered-spider-with-new-telegram-channel-list-organizations-it-attacked\/","title":{"rendered":"Scattered Spider With New Telegram Channel List Organizations It Attacked"},"content":{"rendered":"<p>    Scattered Spider With New Telegram Channel List Organizations It Attacked<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>In early August 2025, a previously quiet cybercrime collective known as Scattered Spider resurfaced with a striking new Telegram channel that aggregates proof of its intrusions and data exfiltration operations.<\/p>\n<p>The channel name fuses ShinyHunters, Scattered Spider, and Lapsus$, signaling a collaboration\u2014or at least a shared brand\u2014among several prolific extortion groups.<\/p>\n<p>Within hours of its launch, the channel published screenshots of console access to Victoria\u2019s Secret, a 100-entry customer data sample from Gucci, and lists of sellable databases from Neiman Marcus and Chanel.<\/p>\n<p>DataBreaches analysts noted that this amalgamated channel has evolved beyond simple leak announcements into an almost real-time marketplace for stolen credentials and corporate documents.<\/p>\n<p>Scattered Spider\u2019s emergence as a public aggregator of multiple <a href=\"https:\/\/cybersecuritynews.com\/everest-ransomware-gang-leak-site-hacked\/\" target=\"_blank\" rel=\"noreferrer noopener\">ransomware<\/a> and data theft campaigns marks a departure from its earlier, more clandestine operations.<\/p>\n<p>Historically, leak channels would post a single statement followed by a download link or sales instructions. In contrast, the new channel intersperses partial data dumps, \u201cHMU if interested\u201d sales pitches, memes, and direct threats to entities like the U.K. Ministry of Justice.<\/p>\n<p>DataBreaches researchers <a href=\"https:\/\/databreaches.net\/2025\/08\/09\/scattered-spider-has-a-new-telegram-channel-to-list-its-attacks\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> scripts posted by the group for enumerating GitHub repositories belonging to the Legal Aid Agency.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiwK1PHZlEWdWfatWG1x6WaIDmFc2m7htxrwnz21Ow0qAJITTKlqGXJ7Upded6OgswIAaSlHkIzUsYobejh-kqr-jx8AmgCPwM-U2Zu4vINWYXLGaBDfXz_tqtu4RILNTsRqBj33qeYZaJWlog4u54vRBljhNnxUqQRiS70izq9iUVASKj9mJfW9jrEnis\/s16000\/ministryofjustice_repos_contents.txt%2520%28Source%2520-%2520DataBreaches.net%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">ministryofjustice_repos_contents.txt (Source \u2013 DataBreaches.net)<\/figcaption><\/figure>\n<\/div>\n<p>This blend of proof and propaganda creates a sense of both transparency and terror.<\/p>\n<p>The channel\u2019s rapid revelations caused immediate alarm across industries. High-value targets including Disney, S&amp;P Global, T-Mobile, Nvidia, Otelier, Coinbase, Burger King Brazil, Adidas, and Cisco were all named, with some incidents tying back to earlier Snowflake and Salesforce campaign leaks.<\/p>\n<p>Government bodies did not escape: the U.S. Department of Homeland Security appeared in multiple posts displaying directory listings of servers, while screenshots hinted at negotiations over stolen court filings.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh3ZMMHpWJw401qBh_biZ7GBs7WIxtrpeDgZYt1qrUsLUtw8OJ5dzAePLCs_wX6kCcr4ogiQhuXeeVfgQYm1f_VvaWY5AZH1Wo3nl_v8nrfYSq3lbD8QiIZbZPHeNwU38QK7E4d0iqvR1eHZh6Q94QasE7E8Z_fYOIKy6SYELDIgZn0htoSeCQbzwLUGKU\/s16000\/DHSDCAS%2520server%2520list%2520%28Source%2520-%2520DataBreaches.net%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">DHSDCAS server list (Source \u2013 DataBreaches.net)<\/figcaption><\/figure>\n<\/div>\n<p>The channel\u2019s frenetic pace and broad scope suggest Scattered Spider may be coordinating or rebranding data theft operations to maximize extortion leverage.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-infection-mechanism\"><strong>Infection Mechanism<\/strong><\/h2>\n<p>Scattered Spider\u2019s infection mechanism leverages a multi-stage approach beginning with spear-phishing and exploited VPN credentials.<\/p>\n<p>Initial access scripts\u2014shared in <a href=\"https:\/\/cybersecuritynews.com\/highly-obfuscated-net-sectoprat\/\" target=\"_blank\" rel=\"noreferrer noopener\">obfuscated<\/a> Python snippets\u2014automate the deployment of Cobalt Strike beacons.<\/p>\n<p>A typical snippet revealed the use of a custom loader that decrypts and injects shellcode into memory without writing to disk:-<\/p>\n<pre class=\"wp-block-code\"><code>import ctypes, base64, subprocess\nshellcode = base64.b64decode(\"...==\")\nptr = ctypes.windll.kernel32.VirtualAlloc(None, len(shellcode), 0x3000, 0x40)\nctypes.memmove(ptr, shellcode, len(shellcode))\nctypes.windll.kernel32.CreateThread(None, 0, ptr, None, 0, None)\nsubprocess.call([\"powershell\", \"-nop\", \"-w\", \"hidden\", \"-c\", \"Invoke-CobaltStrike\"])<\/code><\/pre>\n<p>This in-memory execution evades traditional <a href=\"https:\/\/cybersecuritynews.com\/hackers-launch-zero-day-attacks-to-exploits-corrupted-files-to-evade-security-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">antivirus scanners<\/a> and endpoint detection tools.<\/p>\n<p>Once the beacon is active, Scattered Spider escalates privileges via known Windows kernel vulnerabilities before deploying ransomware\u2014or exfiltrating data for sale\u2014within 48 hours of initial access.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\">Equip your SOC with full access to the latest threat data from\u00a0<strong>ANY.RUN TI Lookup<\/strong>\u00a0that can Improve incident response -&gt;\u00a0<strong><a href=\"https:\/\/any.run\/threat-intelligence-feeds\/?utm_source=csn_aug&amp;utm_medium=article&amp;utm_campaign=how-to-get-real-time-iocs&amp;utm_content=feeds-cta1&amp;utm_term=050825#contact-sales\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Get 14-day\u00a0Free\u00a0Trial<\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/scattered-spider-with-new-telegram-channel\/\">Scattered Spider With New Telegram Channel List Organizations It Attacked<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/scattered-spider-with-new-telegram-channel\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Scattered Spider With New Telegram Channel List Organizations It Attacked In early August 2025, a previously quiet cybercrime collective known as Scattered Spider resurfaced with a striking new Telegram channel that aggregates proof of its intrusions and data exfiltration operations. The channel name fuses ShinyHunters, Scattered Spider, and Lapsus$, signaling a collaboration\u2014or at least a [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-6071","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6071"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6071"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6071\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6071"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6071"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6071"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}