logo

Meet ShinySp1d3r: New Ransomware-as-a-Service created by ShinyHunters

ID: d638ba82-fca9-52c4-b8dc-2cdd9ffb3038

STIX ID: report--d638ba82-fca9-52c4-b8dc-2cdd9ffb3038

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-11-19

Date Updated: 2026-07-18

Author: Lawrence Abrams

...
...

An in-development RaaS called ShinySp1d3r—attributed to ShinyHunters cooperating with Scattered Spider/Lapsus$ affiliates—has surfaced via a Windows encryptor sample on VirusTotal; analysis shows advanced features (ChaCha20 per-file encryption with RSA-2048-protected keys, ETW hooking, process killing, shadow copy deletion, free-space wiping, multiple propagation methods including SCM/WMI/GPO, and anti-analysis) and contains hard-coded ransom notes and leak-site references, with planned Linux/ESXi builds and a fast "lightning" variant.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.