SLH Reportedly Paying $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing
Security researchers have observed a cybercriminal collective calling itself Scattered LAPSUS$ Hunters (SLH) offering substantial cash incentives to bring women into voice-phishing (vishing) schemes aimed at corporate IT support lines. According to a fresh threat advisory from Dataminr, the group is proposing between $500 and $1,000 paid upfront for each successful call, and provides recruits with prewritten scripts to follow during the social-engineering interaction.
The attackers appear to be intentionally expanding their pool of social engineers by seeking female voices, a tactic Dataminr interprets as an attempt to improve impersonation success when contacting help desk staff. The change in recruitment profile is viewed as a deliberate shift designed to evade the sorts of defensive expectations that technicians may be trained to notice.
SLH is a high-profile blend of three criminal factions - LAPSUS$, Scattered Spider, and ShinyHunters - and has a documented history of sophisticated human-targeted attacks. Their playbook commonly includes methods to defeat multi-factor authentication, such as bombing MFA prompts and executing SIM swap scams. Frequently they impersonate legitimate employees while calling help desks or call centers to get password resets or convince staff to install remote monitoring and management (RMM) software that grants attackers remote access.
After gaining that initial foothold, Scattered Spider operators have been seen moving laterally into virtualized environments, escalating privileges, and stealing sensitive corporate information. Some intrusions have culminated in ransomware deployment. To reduce their visibility, the actors often leverage legitimate services and residential proxy networks - for example, services like Luminati and OxyLabs - so their activity blends with normal traffic.
The group also makes use of various tunneling and remote access tools, including Ngrok, Teleport, and Pinggy, and relies on free file-sharing platforms such as file.io, gofile.io, mega.nz, and transfer.sh to stage or move stolen data. These choices allow them to operate using commonly trusted infrastructure while avoiding easy detection.
Palo Alto Networks Unit 42, tracking the same threat under the name Muddled Libra, recently described the collective as extremely adept at manipulating human behavior to achieve identity compromise. In one case investigated in September 2025, Unit 42 reported that after obtaining privileged credentials via a help desk call, the attackers spun up a virtual machine which they used for reconnaissance - including Active Directory enumeration - and tried to exfiltrate Outlook mailbox data and files from a Snowflake instance.
Unit 42 emphasized that the adversary favors legitimate tooling and existing infrastructure to remain inconspicuous, maintaining persistence while focusing on identity and social-engineering techniques. The group has repeatedly targeted Microsoft Azure environments, using the Graph API to reach cloud resources, and employs cloud enumeration utilities such as ADRecon to map and exploit Active Directory environments.
Given the growing reliance on social engineering as an initial attack vector, security teams are being urged to bolster defenses around support channels. Recommendations include training help desk personnel to spot rehearsed scripts and polished vocal impersonations, enforcing strict identity verification processes during support interactions, strengthening MFA by moving away from SMS-based methods, and monitoring audit logs for the creation of new accounts or sudden administrative privilege changes after help desk engagements.
Dataminr characterized the recruitment push as an evolution in SLH’s operational approach: by specifically targeting female voices for vishing roles, the group likely hopes to bypass conventional attacker stereotypes and thereby raise the likelihood of successful impersonation and account takeover.