κατασκευή ιστοσελίδων ρόδος

TECH - WEB DEVELOPMENT NEWS

Get the latest tech - web development news and analysis on industry around the world.

  • HOME
You are here: Home / INDUSTRY NEWS / Cybercrime Groups ShinyHunters, Scattered Spider Join Forces in Extortion Attacks on Businesses
άμυνα
.

Cybercrime Groups ShinyHunters, Scattered Spider Join Forces in Extortion Attacks on Businesses

12/08/2025

Aug 12, 2025Ravie LakshmananCybercrime / Financial Security
An ongoing data extortion campaign targeting Salesforce customers may soon turn its attention to financial services and technology service providers, as ShinyHunters and Scattered Spider appear to be working hand in hand, new findings show.
“This latest wave of ShinyHunters-attributed attacks reveals a dramatic shift in tactics, moving beyond the group’s previous credential theft and database exploitation,” ReliaQuest said in a report shared with The Hacker News.
These include the use of adoption of tactics that mirror those of Scattered Spider, such as highly-targeted vishing (aka voice phishing) and social engineering attacks, leveraging apps that masquerade as legitimate tools, employing Okta-themed phishing pages to trick victims into entering credentials during vishing, and VPN obfuscation for data exfiltration.

ShinyHunters, which first emerged in 2020, is a financially motivated threat group that has orchestrated a series of data breaches targeting major corporations and monetizing them on cybercrime forums like RaidForums and BreachForums. Interestingly, the ShinyHunters persona has been a key participant in these platforms both as a contributor and administrator.
“The ShinyHunters persona partnered with Baphomet to relaunch the second instance of BreachForums (v2) in June 2023 and later launched the June 2025 instance (v4) alone,” Sophos noted in a recent report. “The interim version (v3) abruptly disappeared in April 2025, and the cause is unclear.”
While the relaunch of the forum was short-lived and the bulletin board went offline around June 9, the threat actor has since been linked to attacks targeting Salesforce instances globally, a cluster of extortion-related activity that Google is tracking under the moniker UNC6240.
Coinciding with these developments was the arrest of four individuals suspected of running BreachForums, including ShinyHunters, by French law enforcement authorities. However, the threat actor told DataBreaches.Net that “France rushed to make FALSE, INACCURATE arrests,” raising the possibility that an “associate” member may have been caught.

And that’s not all. On August 8, a new Telegram channel conflating ShinyHunters, Scattered Spider, and LAPSUS$ called “scattered lapsu$ hunters” emerged, with the channel members also claiming to be developing a ransomware-as-a-service solution called ShinySp1d3r that they said will rival LockBit and DragonForce. Three days later, the channel disappeared.
Both Scattered Spider and LAPSUS$ have ties to a broader, nebulous collective dubbed The Com, a notorious network of experienced English-speaking cybercriminals that’s known to engage in a wide range of malicious activities, including SIM swapping, extortion, and physical crime.
ReliaQuest said it has identified a coordinated set of ticket-themed phishing domains and Salesforce credential harvesting pages that are likely created for similar campaigns targeting Salesforce that are aimed at high-profile companies across various industry verticals.

These domains, the company said, were registered using infrastructure typically associated with phishing kits commonly used to host single sign-on (SSO) login pages — a hallmark of Scattered Spider’s attacks impersonating Okta sign-in pages.
Furthermore, an analysis of over 700 domains registered in 2025 that matched Scattered Spider phishing patterns has revealed that domain registrations targeting financial companies have increased by 12% since July 2025, while targeting of technology firms has decreased by 5%, suggesting that banks, insurance companies and financial services could be next in line.
The tactical overlaps aside, that the two groups may be collaborating is borne out by the fact that they have targeted the same sectors (i.e., retail, insurance, and aviation) around the same time.
“Supporting this theory is evidence such as the appearance of a BreachForums’ user with the alias ‘Sp1d3rHunters,’ who was linked to a past ShinyHunters breach, as well as overlapping domain registration patterns,” researchers Kimberley Bromley and Ivan Righi said, adding the account was created in May 2024.
“If these connections are legitimate, they suggest that collaboration or overlap between ShinyHunters and Scattered Spider may have been ongoing for more than a year. The synchronized timing and similar targeting of these previous attacks strongly support the likelihood of coordinated efforts between the two groups.”

Source: thehackernews.com

Filed Under: INDUSTRY NEWS Tagged With: Source-2

3 reasons I switched to and prefer OpenCloud instead of Nextcloud

For years, Nextcloud was my default self-hosted cloud solution. It promised freedom and control, but over time, I ran into several issues: sluggish performance, bloated experience, and an endless stream of minor bugs. I felt stuck in a trade-off between control and usability – until I finally made the leap to OpenCloud. Source: xda-developers.com … [Read More...]

The best advent calendars for 2025: Our top picks from Lego, Pokémon, Funko Pop and more

Who needs ornaments when you can deck the halls with Star Wars builds? This advent calendar delivers 24 surprises, ranging from tiny ships to minifigures in festive outfits. That means you might spot Darth Vader in a scarf or R2-D2 with some seasonal flair. It’s an easy way to make the holidays feel like a Star Wars marathon on Disney+, with new pieces to add to your desk or display shelf every … [Read More...]

Gemini CLI to Your Kali Linux Terminal To Automate Penetration Testing Tasks

With the release of Kali Linux 2025.3, a major update introduces an innovative tool that combines artificial intelligence and cybersecurity: the Gemini Command-Line Interface (CLI). This new open-source package integrates Google’s powerful Gemini AI directly into the terminal, offering penetration testers and security professionals an intelligent assistant designed to streamline and automate … [Read More...]

OxygenOS 16 Launch Date Confirmed; New OnePlus AI Features Expected to Debut With OnePlus 15

OxygenOS 16 will be launched by OnePlus on October 16 in India, the Chinese smartphone maker announced. The new user interface will be built on top of Android 16. It will bring several new redesigned elements to OnePlus handsets, along with a suite of artificial intelligence (AI)-powered features. The upcoming OnePlus 15, the company's next flagship handset, might run OxygenOS 16 out of the box, … [Read More...]

Bitcoin Price Drops to $124,000 After Hitting New All-Time High

The global crypto market opened Monday on a bullish note, as Bitcoin consolidated gains after hitting a new all-time high over the weekend. The world's most widely used digital asset briefly surged past the $125,500 (roughly Rs. 1.1 crore) mark, before dropping to around $124,000 (roughly Rs. 1.1 crore). Ethereum also held strong above $4,500 (roughly Rs. 3.99 lakh), reflecting the momentum that … [Read More...]

Beer Giant Asahi Says Data Stolen in Ransomware Attack

Japanese brewing giant Asahi Group Holdings has confirmed that a ransomware attack has caused the week-long outage at its domestic subsidiaries. The company disclosed the incident last week, blaming order and shipment operational disruptions, and call center downtime on a cyberattack that resulted in system failures. The company, which suspended production at some of its factories in Japan, … [Read More...]

PoC Exploit Released for Sudo Vulnerability that Enables Attackers to Gain Root Access

A publicly available proof-of-concept (PoC) exploit has been released for CVE-2025-32463, a local privilege escalation (LPE) flaw in the Sudo utility that can grant root access under specific configurations.  Security researcher Rich Mirch is credited with identifying the weakness, while a functional PoC and usage guide have been published in an open GitHub repository, accelerating the … [Read More...]

Oracle E-Business Suite Zero-Day Exploited in Cl0p Attacks

The recent data theft and extortion campaign targeting Oracle E-Business Suite customers has been confirmed to be the work of the notorious Cl0p ransomware group, and Oracle has admitted that the hackers have exploited a zero-day vulnerability. The attacks targeting Oracle E-Business Suite (EBS) customers came to light last week, when Google Threat Intelligence Group (GTIG) and Mandiant warned … [Read More...]

Realme GT 8 Pro Spotted in Hands-On Image; Said to Feature 200-Megapixel Telephoto Camera

Realme GT 8 Pro is set to launch in China in October alongside the standard Realme GT 8. The company has teased some key details of the upcoming smartphones. The company previously revealed that the Realme GT 8 Pro variant will feature a swappable rear camera module. A recently leaked live image showcases one of the three designs of the purported interchangeable camera island. A senior company … [Read More...]

Redis Server Vulnerability use-after-free Vulnerability Enables Remote Code Execution

A critical use-after-free vulnerability, identified as CVE-2025-49844, has been discovered in Redis servers, enabling authenticated attackers to achieve remote code execution. This high-severity flaw affects all versions of Redis that utilize the Lua scripting engine, presenting a significant threat to a wide range of deployments that rely on the popular in-memory data store. The core of … [Read More...]

Tags

Source-1 Source-2 Source-3 Source-4 Source-5 Source-6 Source-7 Source-8 Source-9 Source-10 Source-12 Source-13 Source-15 Source-16

Tech Web Development News

This is a PERSONAL and PRIVATE WEBPAGE. Please leave this page. Contact me via email : admin@news-6.com about anything you would like to ask or problem.

Tech News

Disclaimer!
In every post is written below the original source of the post. Copyrights belong on their owners.

Web Development News

HOTELS – CRUISES – CARS – TRAVEL

Recent Posts

  • 3 reasons I switched to and prefer OpenCloud instead of Nextcloud
  • The best advent calendars for 2025: Our top picks from Lego, Pokémon, Funko Pop and more
  • Gemini CLI to Your Kali Linux Terminal To Automate Penetration Testing Tasks
  • OxygenOS 16 Launch Date Confirmed; New OnePlus AI Features Expected to Debut With OnePlus 15
  • Bitcoin Price Drops to $124,000 After Hitting New All-Time High

Technology - Seo

Categories

  • INDUSTRY NEWS

World Industry News

Privacy & Cookies: This site uses cookies.
To find out more, as well as how to remove or block these, see here: Our Cookie Policy
TECH - WEB DEVELOPMENT NEWS @ COPYRIGHTS 2023