CYFIRMA Research

CYFIRMA Research- Resurgence of Scattered Lapsus$ Hunters

CYFIRMA

The threat landscape just got more complex. The Scattered LAPSUS$ Hunters-alliance has re-emerged, merging the tactics of notorious groups.
This isn’t just a name change; it’s a shift toward professionalized, identity-centric extortion.

What you need to know:

  • High-Value Targets: Focused on enterprises with $500M+ revenue, specifically in Cloud, Telecom, and Finance.
  • Identity is the Perimeter: They specialize in "logging in" rather than "hacking in," using advanced vishing (voice phishing) and insider recruitment to bypass MFA.
  • ShinySp1d3r RaaS: The group is launching its own "extortion-as-a-service" platform, moving away from third-party ransomware.
  • Sector Limits: They currently avoid healthcare and specific geopolitical regions (Russia/China), keeping their focus on high-yield corporate data.

The takeaway? If your security relies solely on "traditional" MFA without monitoring for suspicious identity behaviour, you could be at risk.

Link to the Research Report: https://www.cyfirma.com/research/resurgence-of-scattered-lapsus-hunters/

#CyberSecurity #ThreatIntel #ScatteredSpider #Lapsus #CISO #DataProtection #CYFIRMA #CYFIRMAresearch #ExtrnalThreatLandscapeManagement #ETLM

https://www.cyfirma.com/