{"id":11518,"date":"2026-02-06T01:11:45","date_gmt":"2026-02-06T01:11:45","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=11518"},"modified":"2026-02-06T01:11:45","modified_gmt":"2026-02-06T01:11:45","slug":"please-dont-feed-the-scattered-lapsus-shinyhunters-krebs-on-safety","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=11518","title":{"rendered":"Please Don\u2019t Feed the Scattered Lapsus ShinyHunters \u2013 Krebs on Safety"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>A prolific knowledge ransom gang that calls itself <strong>Scattered Lapsus ShinyHunters<\/strong> (SLSH) has a particular playbook when it seeks to extort fee from sufferer companies: Harassing, threatening and even swatting executives and their households, all whereas notifying journalists and regulators in regards to the extent of the intrusion. Some victims reportedly are paying \u2014 maybe as a lot to include the stolen knowledge as to cease the escalating private assaults. However a prime SLSH professional warns that partaking in any respect past a \u201cWe\u2019re not paying\u201d response solely encourages additional harassment, noting that the group\u2019s fractious and unreliable historical past means the one profitable transfer is to not pay.<\/p>\n<div id=\"attachment_73160\" style=\"width: 758px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" aria-describedby=\"caption-attachment-73160\" decoding=\"async\" class=\" wp-image-73160\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/02\/dontfeed.png\" alt=\"\" width=\"748\" height=\"746\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/02\/dontfeed.png 915w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/02\/dontfeed-768x766.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/02\/dontfeed-782x780.png 782w\" sizes=\"auto, (max-width: 748px) 100vw, 748px\"\/><\/p>\n<p id=\"caption-attachment-73160\" class=\"wp-caption-text\">Picture: Shutterstock.com, @Mungujakisa<\/p>\n<\/div>\n<p>Not like conventional, extremely regimented Russia-based ransomware affiliate teams, SLSH is an unruly and considerably fluid English-language extortion gang that seems tired of constructing a status of constant habits whereby victims might need some measure of confidence that the criminals will hold their phrase if paid.<\/p>\n<p>That\u2019s in keeping with <strong>Allison Nixon<\/strong>, director of analysis on the New York Metropolis based mostly safety consultancy <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/unit221b.com\" target=\"_blank\" rel=\"noopener\">Unit 221B<\/a>. Nixon has been intently monitoring the prison group and particular person members as they bounce between numerous Telegram channels used to extort and harass victims, and he or she mentioned SLSH differs from conventional knowledge ransom teams in different vital ways in which argue towards trusting them to do something they are saying they\u2019ll do \u2014 comparable to destroying stolen knowledge.<\/p>\n<p>Like SLSH, many conventional Russian ransomware teams have employed high-pressure ways to power fee in alternate for a decryption key and\/or a promise to delete stolen knowledge, comparable to publishing a darkish net shaming weblog with samples of stolen knowledge subsequent to a countdown clock, or notifying journalists and board members of the sufferer firm. However Nixon mentioned the extortion from SLSH shortly escalates method past that \u2014 to threats of bodily violence towards executives and their households, DDoS assaults on the sufferer\u2019s web site, and repeated email-flooding campaigns.<\/p>\n<p>SLSH is thought for breaking into corporations by phishing workers over the telephone, and utilizing the purloined entry to steal delicate inner knowledge. In <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/expansion-shinyhunters-saas-data-theft\" target=\"_blank\" rel=\"noopener\">a January 30 weblog publish<\/a>, Google\u2019s safety forensics agency <strong>Mandiant<\/strong> mentioned SLSH\u2019s most up-to-date extortion assaults stem from incidents spanning early to mid-January 2026, when SLSH members pretended to be IT workers and referred to as workers at focused sufferer organizations claiming that the corporate was updating MFA settings.<\/p>\n<p>\u201cThe risk actor directed the workers to victim-branded credential harvesting websites to seize their SSO credentials and MFA codes, after which registered their very own gadget for MFA,\u201d the weblog publish defined.<\/p>\n<p>Victims usually first study of the breach when their model title is uttered on no matter ephemeral new public Telegram group chat SLSH is utilizing to threaten, extort and harass their prey. In response to Nixon, the coordinated harassment on the SLSH Telegram channels is a part of a well-orchestrated technique to overwhelm the sufferer group by manufacturing humiliation that pushes them over the edge to pay.<\/p>\n<p>Nixon mentioned a number of executives at focused organizations have been topic to \u201cswatting\u201d assaults, whereby SLSH communicated a phony bomb risk or hostage state of affairs on the goal\u2019s deal with within the hopes of eliciting a closely armed police response at their dwelling or workplace.<\/p>\n<p>\u201cAn enormous a part of what they\u2019re doing to victims is the psychological side of it, like harassing executives\u2019 youngsters and threatening the board of the corporate,\u201d Nixon informed KrebsOnSecurity. \u201cAnd whereas these victims are getting extortion calls for, they\u2019re concurrently getting outreach from media shops saying, \u2018Hey, do you have got any feedback on the unhealthy issues we\u2019re going to put in writing about you.\u201d<\/p>\n<p>In <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blog.unit221b.com\/dont-read-this-blog\/harassment-scare-tactics-why-victims-should-never-pay-shinyhunters\" target=\"_blank\" rel=\"noopener\">a weblog publish at present<\/a>, Unit 221B argues that nobody ought to negotiate with SLSH as a result of the group has demonstrated a willingness to extort victims based mostly on guarantees that it has no intention to maintain. Nixon factors out that every one of SLSH\u2019s recognized members hail from <strong>The Com<\/strong>, shorthand for a constellation of cybercrime-focused Discord and Telegram communities which function a type of <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2024\/09\/the-dark-nexus-between-harm-groups-and-the-com\/\" target=\"_blank\" rel=\"noopener\">distributed social community that facilitates prompt collaboration<\/a>.<\/p>\n<p>Nixon mentioned Com-based extortion teams are inclined to instigate feuds and drama between group members, resulting in mendacity, betrayals, credibility destroying habits, backstabbing, and sabotaging one another.<\/p>\n<p>\u201cWith any such ongoing dysfunction, usually compounding by substance abuse, these risk actors usually aren\u2019t capable of act with the core objective in thoughts of finishing a profitable, strategic ransom operation,\u201d Nixon wrote. \u201cThey frequently lose management with outbursts that put their technique and operational safety in danger, which severely limits their skill to construct an expert, scalable, and complicated prison group community for continued profitable ransoms \u2013 in contrast to different, extra tenured {and professional} prison organizations targeted on ransomware alone.\u201d<\/p>\n<p>Intrusions from established ransomware teams sometimes focus on encryption\/decryption malware that principally stays on the affected machine. In distinction, Nixon mentioned, ransom from a Com group is usually structured the identical as violent sextortion schemes towards minors, whereby members of The Com will steal damaging info, threaten to launch it, and \u201cpromise\u201d to delete it if the sufferer complies with none assure or technical proof level that they&#8217;ll hold their phrase. She writes:<\/p>\n<p>A key part of SLSH\u2019s efforts to persuade victims to pay, Nixon mentioned, entails manipulating the media into hyping the risk posed by this group. This strategy additionally borrows a web page from the playbook of sextortion assaults, she mentioned, which inspires predators to maintain targets repeatedly engaged and worrying in regards to the penalties of non-compliance.<\/p>\n<p>\u201cOn days the place SLSH had no substantial prison \u2018win\u2019 to announce, they targeted on asserting demise threats and harassment to maintain regulation enforcement, journalists, and cybercrime business professionals targeted on this group,\u201d she mentioned.<\/p>\n<div id=\"attachment_73163\" style=\"width: 758px\" class=\"wp-caption aligncenter\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/02\/comtutsh.png\" target=\"_blank\" rel=\"noopener\"><img aria-describedby=\"caption-attachment-73163\" decoding=\"async\" loading=\"lazy\" class=\"wp-image-73163\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/02\/comtutsh.png\" alt=\"\" width=\"748\" height=\"92\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/02\/comtutsh.png 935w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/02\/comtutsh-768x94.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/02\/comtutsh-782x96.png 782w\" sizes=\"auto, (max-width: 748px) 100vw, 748px\"\/><\/a><\/p>\n<p id=\"caption-attachment-73163\" class=\"wp-caption-text\">An excerpt from a sextortion tutorial from a Com-based Telegram channel. Picture: Unit 221B.<\/p>\n<\/div>\n<p>Nixon is aware of a factor or two about being threatened by SLSH: For the previous a number of months, the group\u2019s Telegram channels have been replete with threats of bodily violence towards her, towards Yours Really, and towards different safety researchers. These threats, she mentioned, are simply one other method the group seeks to generate media consideration and obtain a veneer of credibility, however they&#8217;re helpful as indicators of compromise as a result of SLSH members have a tendency to call drop and malign safety researchers even of their communications with victims.<\/p>\n<p>\u201cLook ahead to the next behaviors of their communications to you or their public statements,\u201d Unit 221B\u2019s advisory reads. \u201cRepeated abusive mentions of Allison Nixon (or \u201cA.N\u201d), Unit 221B, or cybersecurity journalists\u2014particularly Brian Krebs\u2014or every other cybersecurity worker, or cybersecurity firm. Any threats to kill, or commit terrorism, or violence towards inner workers, cybersecurity workers, investigators, and journalists.\u201d<\/p>\n<p>Unit 221B says that whereas the strain marketing campaign throughout an extortion try could also be traumatizing to workers, executives, and their relations, coming into into drawn-out negotiations with SLSH incentivizes the group to extend the extent of hurt and danger, which might embrace the bodily security of workers and their households.<\/p>\n<p>\u201cThe breached knowledge won&#8217;t ever return to the way in which it was, however we are able to guarantee you that the harassment will finish,\u201d Nixon mentioned. \u201cSo, your determination to pay must be a separate situation from the harassment. We consider that once you separate these points, you&#8217;ll objectively see that the most effective plan of action to guard your pursuits, in each the brief and long run, is to refuse fee.\u201d<\/p>\n<\/p><\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>A prolific knowledge ransom gang that calls itself Scattered Lapsus ShinyHunters (SLSH) has a particular playbook when it seeks to extort fee from sufferer companies: Harassing, threatening and even swatting executives and their households, all whereas notifying journalists and regulators in regards to the extent of the intrusion. Some victims reportedly are paying \u2014 maybe [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":11520,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[2476,7723,262,5711,2075,211,5450],"class_list":["post-11518","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-dont","tag-feed","tag-krebs","tag-lapsus","tag-scattered","tag-security","tag-shinyhunters"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/11518","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=11518"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/11518\/revisions"}],"predecessor-version":[{"id":11519,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/11518\/revisions\/11519"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/11520"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=11518"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=11518"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=11518"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-15 10:45:59 UTC -->