logo

Anatomy of the Red Hat Intrusion: Crimson Collective and SLSH Extortions

ID: c240fc16-b0d3-5b67-9437-b251512cd38d

STIX ID: report--c240fc16-b0d3-5b67-9437-b251512cd38d

Feed Name: Seqrite Blog

Threat Score
88/100

Date Published: 2025-10-24

Date Updated: 2026-04-30

Author: Seqrite

...
...

The report documents the rise of a hybrid extortion collective (Scattered LAPSUS$ Shiny Hunters) that combines social engineering, shared exploit code, and third‑party compromises to steal and extort data. It highlights in‑the‑wild exploitation of Oracle E-Business Suite (CVE-2025-61882) and potential abuse of a critical Red Hat OpenShift AI flaw (CVE-2025-10725), large-scale data leaks (Discord, Red Hat, multiple corporate victims), distribution of AsyncRAT via malicious lures, and the group’s shift toward offering Extortion‑as‑a‑Service and recruiting insiders for persistent access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.