Three well-known threat groups have consolidated into a unified cybercriminal entity that represents a significant shift in underground tactics.
Scattered LAPSUS$ Hunters (SLH) emerged in early August 2025 as a federated alliance combining Scattered Spider, ShinyHunters, and LAPSUS$, creating what researchers describe as the first consolidated alliance among mature cybercriminal clusters.
.webp)
This consolidation marks a deliberate strategic move within the cybercriminal underground, where established threat actors are merging reputational assets and operational capabilities to create a more formidable collective.
The alliance entered the threat landscape through Telegram, leveraging the platform as its primary operational base and marketing channel.
.webp)
Unlike traditional cybercriminal actors who maintain minimal visibility, SLH adopted a highly performative approach, combining sensationalist messaging with proof-of-compromise announcements and public engagement strategies.
The group’s first verified channel appeared on August 8, 2025, establishing what would become a consistent pattern of theatrical branding and coordinated communication that blurs the line between attention-driven hacktivism and financially motivated cybercrime.
Since its inception, Trustwave analysts have noted that the group has demonstrated remarkable operational persistence despite repeated platform disruptions.
Telegram channels have been removed and recreated at least sixteen times under varying name iterations, yet SLH consistently re-established its presence within hours, signaling extraordinary determination to maintain public visibility and control over narrative construction.
Trustwave researchers identified sophisticated technical capabilities underlying SLH’s operations.
Technical Infrastructure and Exploitation Capabilities
The collective exhibits genuine exploit development and acquisition competencies, particularly targeting high-value enterprise systems including CRM platforms, Database Management Systems, and SaaS infrastructure.
Members leverage AI-automated vishing campaigns combined with credential harvesting techniques, followed by systematic lateral movement for privilege escalation and rapid data exfiltration.
Notable vulnerabilities tied to SLH operations include CVE-2025-61882 (Oracle E-Business Suite) and claims of exploitation targeting CVE-2025-31324 (SAP NetWeaver), suggesting capability development or code acquisition from external sources.
Code snippets circulated within channels demonstrate legitimate exploit proof-of-concepts, while documented local privilege escalation techniques show command execution access to sensitive system files.
This technical arsenal reflects convergence of skills drawn from the three merged organizations, enabling simultaneous deployment of social engineering, exploitation, and extortion methodologies that amplify operational impact across their targets and enhance their market positioning within the cybercriminal ecosystem.
Follow us on Google News, LinkedIn, and X to Get More Instant Updates, Set CSN as a Preferred Source in Google.
The post Three Infamous Cybercriminal Groups Form a New Alliance Dubbed ‘Scattered LAPSUS$ Hunters’ appeared first on Cyber Security News.



.webp)