{"id":7250,"date":"2025-09-27T10:03:28","date_gmt":"2025-09-27T10:03:28","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/09\/27\/researchers-uncovered-connections-between-lapsus-scattered-spider-and-shinyhunters-hacker-groups\/"},"modified":"2025-09-27T10:03:28","modified_gmt":"2025-09-27T10:03:28","slug":"researchers-uncovered-connections-between-lapsus-scattered-spider-and-shinyhunters-hacker-groups","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/09\/27\/researchers-uncovered-connections-between-lapsus-scattered-spider-and-shinyhunters-hacker-groups\/","title":{"rendered":"Researchers Uncovered Connections Between LAPSUS$, Scattered Spider, and ShinyHunters Hacker Groups"},"content":{"rendered":"<p>    Researchers Uncovered Connections Between LAPSUS$, Scattered Spider, and ShinyHunters Hacker Groups<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The cybersecurity landscape continues to evolve as three of the most notorious English-speaking cybercrime groups\u2014LAPSUS$, Scattered Spider, and ShinyHunters\u2014have been found to share significant operational connections, tactical overlaps, and direct collaboration since 2023.<\/p>\n<p>These relationships have created what security experts now describe as a highly adaptive cybercrime ecosystem that poses an advanced persistent threat to global enterprises.<\/p>\n<p>Recent developments reveal that the lines between these groups have become increasingly blurred, with their shared proclivity for social engineering, overlapping membership, and coordinated attacks on high-profile targets demonstrating a level of organization previously unseen in cybercrime operations.<\/p>\n<p>The attack vectors employed by these groups are not particularly sophisticated in terms of technical complexity but showcase remarkable coordination and exploitation of both human weaknesses and technological misconfigurations.<\/p>\n<p>Their primary method of gaining access to target networks remains social engineering-based attacks, where actors impersonate employees or contractors to deceive IT help desks into granting <a href=\"https:\/\/cybersecuritynews.com\/unauthorized-access-attempts-in-active-directory\/\" target=\"_blank\" rel=\"noreferrer noopener\">unauthorized access<\/a>.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjWaGiEi1OnKwci4NFwMzVJQAUQ3SsS_Qp0SXupCswGxu2Z4cwtT4xYDPhVaGd79fwL0rW2GxtIShZ1iGDTJ_VY9DHekT4vZMt-ePHSLiM0KLYuKW-tYd6viF6V5drr9UEWJKoG8NOuB-m-jfeJH4THy2hMGuuV3BUCjAHI7YnumMe5uzxhAYY7vYNb1wc\/s16000\/Extortion%2520email%2520%28Source%2520-%2520Resecurity%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Extortion email (Source \u2013 Resecurity)<\/figcaption><\/figure>\n<\/div>\n<p>Despite their \u201cretirement\u201d announcement in September 2025, intelligence suggests these groups continue operating discreetly, having established substantial credibility and a proven track record of successful breaches that allows them to leverage their commanding reputation for private extortion without immediate media amplification.<\/p>\n<p>Resecurity analysts <a href=\"https:\/\/www.resecurity.com\/blog\/article\/trinity-of-chaos-the-lapsus-shinyhunters-and-scattered-spider-alliance-embarks-on-global-cybercrime-spree\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> the most concrete evidence of collaboration in August 2025 when a Telegram channel explicitly combined the brands and apparent memberships of all three groups.<\/p>\n<p>This chaotic channel, eventually banned by Telegram, was used to coordinate threats, tease data leaks, and market a new Ransomware-as-a-Service offering dubbed \u201cshinysp1d3r.\u201d<\/p>\n<p>The operational division of labor became clear: ShinyHunters confirmed that Scattered Spider provided initial access to targets while they handled data exfiltration and dumps, with LAPSUS$ members serving as active participants in high-profile campaigns including the Salesforce and Snowflake breaches.<\/p>\n<p>The groups\u2019 association with \u201cThe Com\u201d collective further demonstrates their interconnected nature.<\/p>\n<p>This predominantly English-speaking cybercriminal ecosystem operates as a loosely organized network encompassing a broad range of actors, mainly teenagers and individuals in their twenties.<\/p>\n<p>The amplification of successful data breaches through official Com channels suggests shared ideology, membership, resources, and possible operational coordination, prompting the FBI to issue warnings about the risks associated with joining such movements.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-social-engineering-and-multi-factor-authentication-bypass-techniques\"><strong>Social Engineering and Multi-Factor Authentication Bypass Techniques<\/strong><\/h2>\n<p>The trinity of hacker groups has refined sophisticated social engineering methodologies that serve as their primary attack vector, with particular expertise in bypassing modern security controls that many organizations consider robust.<\/p>\n<p>Their approach to multi-factor authentication (MFA) circumvention demonstrates the evolution of social engineering from simple phishing to complex, multi-stage psychological manipulation campaigns.<\/p>\n<p>LAPSUS$ pioneered the use of SIM swapping combined with MFA bombing techniques, also known as \u201cpush fatigue,\u201d where attackers flood victims with authentication requests until they approve one out of frustration or confusion.<\/p>\n<p>This technique has been widely adopted by Scattered Spider and increasingly used by ShinyHunters in their Salesforce-focused campaigns.<\/p>\n<p>The groups employ sophisticated vishing (voice phishing) operations where attackers impersonate IT staff members, often armed with detailed organizational knowledge obtained through reconnaissance or previous breaches.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhbvNTst9XBT8IuVlv4GY5f64vlDhiU6vX8KVX5QaALn17Y6jWNwXATUM-cl35stpumKgLWXKzew_0L8cviW_-t4rkZXQacgfhafD2BMNQop2s-7HUVm6J8LMhdXQGzHrGgCm4Ix2q-DhYT374ODLNZZrDY7nmbuuBkpv_CKyUutGbdohRSK4uQA-J11lw\/s16000\/Attack%2520on%2520Jaguar%2520Land%2520Rover%2520%28JLR%29%2520%28Source%2520-%2520Resecurity%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Attack on Jaguar Land Rover (JLR) (Source \u2013 Resecurity)<\/figcaption><\/figure>\n<\/div>\n<p>Their help desk impersonation techniques involve extensive preparation, including gathering employee names, organizational structures, and internal terminology through social media <a href=\"https:\/\/cybersecuritynews.com\/morphing-meerkat-phaas-using-dns-reconnaissance\/\" target=\"_blank\" rel=\"noreferrer noopener\">reconnaissance<\/a> and data broker services.<\/p>\n<p>Attackers often call help desks claiming to be employees who have lost their devices or been locked out of accounts, providing enough authentic-seeming information to convince support staff to reset credentials or provide access.<\/p>\n<p>In OAuth token abuse scenarios, particularly targeting Salesforce environments, the groups exploit the trust relationship between applications and cloud services.<\/p>\n<p>The technical implementation involves tricking users into authorizing malicious \u201cConnected Apps\u201d in Salesforce, which generates long-lived OAuth tokens that grant persistent access to data while bypassing <a href=\"https:\/\/cybersecuritynews.com\/aitm-phishing-kits-bypassing-mfa\/\" target=\"_blank\" rel=\"noreferrer noopener\">MFA<\/a> and other security controls.<\/p>\n<p>These tokens, once obtained, allow attackers to access customer relationship management (CRM) data at scale, as demonstrated in ShinyHunters\u2019 claims of stealing over 1.5 billion Salesforce records from 760 companies.<\/p>\n<p>The abuse of OAuth tokens associated with legitimate integrations like Salesloft and Drift showcases how attackers exploit the interconnected nature of modern cloud environments to maintain persistent access while appearing as legitimate application traffic.<\/p>\n<p>Infostealers play a crucial role in their authentication bypass strategy, with the groups utilizing malware families including Azorult, Lumma, RedLine, <a href=\"https:\/\/cybersecuritynews.com\/raccoon-infostealer-admin-arrested\/\" target=\"_blank\" rel=\"noreferrer noopener\">Raccoon<\/a>, and Vidar to harvest not only usernames and passwords but also active session cookies.<\/p>\n<p>These cookies allow attackers to hijack authenticated sessions and gain immediate access to systems without triggering login alerts or MFA challenges.<\/p>\n<p>The sophisticated nature of these attacks demonstrates how traditional security measures often fail against well-orchestrated <a href=\"https:\/\/cybersecuritynews.com\/social-engineering-tactics\/\" target=\"_blank\" rel=\"noreferrer noopener\">social engineering<\/a> campaigns that combine technical exploitation with psychological manipulation, making detection and prevention increasingly challenging for organizations relying solely on technological solutions.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/researchers-uncovered-connections-between-lapsus-scattered-spider\/\">Researchers Uncovered Connections Between LAPSUS$, Scattered Spider, and ShinyHunters Hacker Groups<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/researchers-uncovered-connections-between-lapsus-scattered-spider\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Researchers Uncovered Connections Between LAPSUS$, Scattered Spider, and ShinyHunters Hacker Groups The cybersecurity landscape continues to evolve as three of the most notorious English-speaking cybercrime groups\u2014LAPSUS$, Scattered Spider, and ShinyHunters\u2014have been found to share significant operational connections, tactical overlaps, and direct collaboration since 2023. These relationships have created what security experts now describe as a [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-7250","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7250"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7250"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7250\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7250"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7250"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7250"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}