The Golden Scale: Bling Libra and the Evolving Extortion Economy

The Golden Scale: Bling Libra and the Evolving Extortion Economy

Scattered Lapsus$ Hunters (aka SP1D3R HUNTERS, SLSH) and affiliated groups like Bling Libra and Crimson Collective have been conducting large-scale data theft from Salesforce tenants and other cloud environments and are operating an extortion-as-a-service (EaaS) model to monetize stolen data. The activity has targeted retail and hospitality organizations and cloud providers (e.g., Red Hat, AWS), prompting recommendations such as scanning for exposed secrets, implementing zero trust controls, and participating in sector ISACs. #BlingLibra #CrimsonCollective

Keypoints

  • Scattered Lapsus$ Hunters (also called Trinity of Chaos) claims over 1 billion stolen Salesforce records across coordinated campaigns and lists 39 organizations on its data leak site with ransom deadlines.
  • Bling Libra operates as an extortion-as-a-service (EaaS) provider, taking revenue shares (25–30%) and recruiting collaborators to send extortion emails to executives.
  • Crimson Collective emerged recently, claiming a breach of Red Hat (GitLab instance) with ~570 GB exfiltrated and around 800 Customer Engagement Reports among stolen items.
  • The groups focus on cloud platforms (Salesforce, AWS) and use data leak sites and Telegram channels to publicize victims and pressure payments rather than deploying file-encrypting ransomware.
  • Law enforcement seized BreachForums-related domains (affecting the clearnet DLS), but actors claim darknet DLS and members remain at large and continue threatening data release deadlines.
  • Retail and hospitality organizations face risks including identity theft, account takeover, returns/gift-card fraud, and loyalty rewards fraud leading to fraudulent travel services.
  • Recommended defenses include secret-scanning tools (e.g., TruffleHog), zero trust controls (conditional access, least privilege), and participation in sector ISACs like RH-ISAC.

MITRE Techniques

  • [T1078 ] Valid Accounts – Actors breached cloud and SaaS tenants (Salesforce, AWS, GitLab) to access data and exfiltrate records. Quote: ‘they have asserted responsibility for laying siege to customer Salesforce tenants…’
  • [T1537 ] Transfer Data to Cloud Account – Exfiltration of large datasets (e.g., 570 GB from Red Hat GitLab) to attacker-controlled locations for extortion. Quote: ‘claimed to have exfiltrated approximately 570 GB of compressed data from more than 28,000 internal development repositories.’”
  • [T1499 ] Data Staged – Stolen Salesforce records and other data posted to a data leak site (DLS) and prepared for public release as extortion leverage. Quote: ‘posted the names of 39 global organizations from which they claim to have stolen Salesforce data’”
  • [T1592 ] Gather Victim Identity Information – Theft of customer records enabling identity theft, account takeover, and social engineering targeting retail and hospitality customers. Quote: ‘the theft of customer data can lead to outcomes such as identity theft…’
  • [T1598 ] Phishing for Information (Extortion Emails) – Recruitment and use of collaborators to send extortion notes via email to company executives to pressure payment. Quote: ‘they are also recruiting other threat actors to help send extortion notes to victims via email, specifically focusing on communicating with executives.’”
  • [T1190 ] Exploit Public-Facing Application – Breach into Red Hat GitLab instance used to steal internal repositories and client reports. Quote: ‘Red Hat confirmed the root cause as a breach into one of its GitLab instances.’”

Indicators of Compromise

  • [Domain ] Data leak site hosting and BreachForums-related domain seizure – Bling Libra’s DLS hosted on a domain previously associated with BreachForums (clearnet domain seized by FBI).
  • [File/Repository ] Large exfiltrated repository data – ~570 GB of compressed data from Red Hat GitLab, including ~800 Customer Engagement Reports.
  • [Victim List / Org Names ] Publicly listed victims on DLS – 39 global organizations claimed as Salesforce victims (examples withheld by source reporting).
  • [Platform/Service ] Targeted cloud services – Salesforce tenants and AWS environments targeted for credential and data theft (example contexts: stolen Salesforce records; AWS intrusions documented previously).


Read more: https://unit42.paloaltonetworks.com/scattered-lapsus-hunters/