Meet ShinySp1d3r: New Ransomware-as-a-Service created by ShinyHunters
ID: d638ba82-fca9-52c4-b8dc-2cdd9ffb3038
STIX ID: report--d638ba82-fca9-52c4-b8dc-2cdd9ffb3038
Feed Name: Bleeping Computer
An in-development RaaS called ShinySp1d3r—attributed to ShinyHunters cooperating with Scattered Spider/Lapsus$ affiliates—has surfaced via a Windows encryptor sample on VirusTotal; analysis shows advanced features (ChaCha20 per-file encryption with RSA-2048-protected keys, ETW hooking, process killing, shadow copy deletion, free-space wiping, multiple propagation methods including SCM/WMI/GPO, and anti-analysis) and contains hard-coded ransom notes and leak-site references, with planned Linux/ESXi builds and a fast "lightning" variant.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
