logo

The COM: Anatomy of an English-Speaking Cybercriminal Ecosystem And The Origins of Scattered Lapsus$ Hunters

ID: 26c2a9cf-f84d-5abc-bce6-e39fe3592274

STIX ID: report--26c2a9cf-f84d-5abc-bce6-e39fe3592274

Feed Name: CloudSEK Blog

Threat Score
82/100

Date Published: 2025-11-11

Date Updated: 2026-04-27

...
...

The report analyzes the evolution of an English‑speaking cybercriminal ecosystem called “The COM,” tracing its roots in OGUsers and RaidForums to a modern, service-oriented criminal market that combines social engineering (callers/texters, SIM swapping) with breach-focused actors (IABs, exfiltration teams). It profiles prominent groups (Lapsus$, ShinyHunters, Scattered Spider, SRG), documents major disruptions and forum takedowns, highlights the modular ‘as‑a‑service’ supply chain that frustrates traditional IOC detection, and recommends identity‑centric defenses, phishing‑resistant MFA, and insider‑focused controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.