ShinyHunters is a cyber criminal collective that has been active since at least 2019 operating under the ShinyCorp persona. ShinyHunters has targeted multiple industries and geographic regions gathering legitimate credentials and personally identifiable information (PII) for resale or extortion of victims. ShinyHunters has been associated with the broader collective called The Community, also known as The Com whose members have also included Scattered Spider and LAPSUS$. Public reporting has mentioned a variety of names for operations ShinyHunters members have reportedly conducted with members of other groups, including "Scattered Lapsus Hunters," "Scattered Lapsus Shiny Hunters," and "SLSH."[1][2][3][4][5][6][7][8]
| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1583 | .001 | Acquire Infrastructure: Domains |
ShinyHunters has established clearnet and Tor data leak sites (DLS) including one named "SHINYHUNTERS" for the exfiltration and posting of stolen data.[7][5] Additionally, ShinyHunters has registered domains that mimic legitimate Microsoft Azure NetApp Files endpoints, such as azurenetfiles[.]net, and legitimate Okta SSO login pages, such as trial-6857053.okta[.]com.[6][1] |
| .004 | Acquire Infrastructure: Server |
ShinyHunters has used five IP addresses to host Python SimpleHTTP servers on port 8888, which exposed staging materials, customized agents, and .bash_history files.[6] |
||
| Enterprise | T1595 | .002 | Active Scanning: Vulnerability Scanning |
ShinyHunters has searched through victim companies’ GitHub repositories for vulnerabilities.[2] |
| Enterprise | T1560 | .002 | Archive Collected Data: Archive via Library |
ShinyHunters has used the following command to compress collected data: |
| Enterprise | T1110 | Brute Force |
ShinyHunters has performed brute force attacks against edge devices, such as VPNs or firewall solutions.[1] |
|
| Enterprise | T1580 | Cloud Infrastructure Discovery |
ShinyHunters has used Amazon Simple Storage Service (S3) Browser and WinSCP to collect information on S3 bucket configurations.[3][2] |
|
| Enterprise | T1619 | Cloud Storage Object Discovery |
ShinyHunters has used Amazon Simple Storage Service (S3) Browser and WinSCP to access S3 objects.[3] |
|
| Enterprise | T1059 | .007 | Command and Scripting Interpreter: JavaScript |
ShinyHunters has used the MeshCentral command-line interface utility meshctrl.js and npm to interact with compromised systems. Specifically for npm, ShinyHunters has checked for the authenticode tool using the command |
| .009 | Command and Scripting Interpreter: Cloud API |
ShinyHunters has used the AWS Command Line Interface (CLI) for operations to include a variety of API calls, such as |
||
| Enterprise | T1485 | Data Destruction |
ShinyHunters has executed the |
|
| Enterprise | T1530 | Data from Cloud Storage |
ShinyHunters has collected data from insecure cloud buckets.[2] |
|
| Enterprise | T1213 | .003 | Data from Information Repositories: Code Repositories |
ShinyHunters has gathered information from and has searched for vulnerabilities in the target company’s GitHub repository source code.[4] |
| .006 | Data from Information Repositories: Databases |
ShinyHunters has collected Salesforce datasets from victims in the airline and retail sectors.[1] |
||
| Enterprise | T1491 | .001 | Defacement: Internal Defacement |
ShinyHunters has left ransom notes titled README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT.[6] |
| Enterprise | T1587 | .004 | Develop Capabilities: Exploits |
ShinyHunters has exploited zero-day vulnerability CVE-2026-35273 against Oracle PeopleSoft application infrastructure.[6] |
| Enterprise | T1573 | .002 | Encrypted Channel: Asymmetric Cryptography |
ShinyHunters has established a connection between the staging host and the C2 using SSH.[6] |
| Enterprise | T1585 | .002 | Establish Accounts: Email Accounts |
ShinyHunters has established multiple email accounts, such as shinycorp@tutonota[.]com, for use in extortion activities.[8][3] |
| Enterprise | T1567 | Exfiltration Over Web Service |
ShinyHunters has used compromised Salesforce CRM (Customer Relationship Management) dashboards to exfiltrate bulk data. Additionally, ShinyHunters has used LimeWire, a file-sharing service, to showcase samples of stolen data.[1] |
|
| Enterprise | T1190 | Exploit Public-Facing Application |
ShinyHunters has exploited CVE-2026-35273 against Oracle PeopleSoft application infrastructure.[6] ShinyHunters has exploited known vulnerabilities in internet-facing servers.[1] |
|
| Enterprise | T1203 | Exploitation for Client Execution |
ShinyHunters has exploited vulnerabilities in the target company’s GitHub repository source code to enable more complex follow-on third-party or supply chain attacks.[4] |
|
| Enterprise | T1210 | Exploitation of Remote Services |
ShinyHunters has exploited vulnerabilities in remote services for lateral movement.[2] |
|
| Enterprise | T1083 | File and Directory Discovery |
ShinyHunters has checked mount points for Oracle PeopleSoft configurations and has checked the process scheduler configuration file psappsrv.cfg. Additionally, ShinyHunters has read WebLogic server XML configurations files (config.xml).[6] |
|
| Enterprise | T1657 | Financial Theft |
ShinyHunters has called or sent text messages or emails to employees of victim organizations to demand payment in Bitcoin within 72 hours. Email addresses used in extortion activities include shinycorp@tuta[.]com, shinygroup@tuta[.]com, shinycorp@tutanota[.]com, and shinygroup@onionmail[.]com.[8][7][5][4][3][2][1] |
|
| Enterprise | T1589 | .001 | Gather Victim Identity Information: Credentials |
ShinyHunters has collected credentials containing PII, ultimately selling the information on their DLS.[4][3] |
| Enterprise | T1105 | Ingress Tool Transfer |
ShinyHunters has deployed custom scripts to targeted systems from customized MeshAgents in their staging environment.[6] |
|
| Enterprise | T1036 | .005 | Masquerading: Match Legitimate Resource Name or Location |
ShinyHunters has disguised MeshCentral agent binaries as Microsoft Azure services, e.g. meshagent32-azure-ops.exe, meshagent64-azure-ops.exe, and meshagent64-v2.exe.[6] |
| Enterprise | T1588 | .002 | Obtain Capabilities: Tool |
ShinyHunters has obtained MeshCentral to deploy agents masquerading as legitimate cloud endpoints.[6] ShinyHunters has obtained WinSCP to gather information on S3 bucket configurations.[3] ShinyHunters has obtained ConnectWise and other RMM tools to gain initial access.[1] |
| .007 | Obtain Capabilities: Artificial Intelligence |
ShinyHunters has used Bland AI to create conversational pathways tailored to specific scenarios during voice phishing attacks.[1] |
||
| Enterprise | T1069 | .003 | Permission Groups Discovery: Cloud Groups |
ShinyHunters has executed API calls to enumerate permissions for compromised AWS accounts.[3] |
| Enterprise | T1598 | Phishing for Information |
ShinyHunters has sent phishing emails to Microsoft Office 365 corporate users in order to steal credentials.[4] |
|
| .003 | Spearphishing Link |
ShinyHunters has used spearphishing emails with malicious links to gain initial access and credentials.[2] |
||
| Enterprise | T1090 | .003 | Proxy: Multi-hop Proxy |
ShinyHunters has used Tor to host their DLS.[5] |
| Enterprise | T1219 | Remote Access Tools |
ShinyHunters has used MeshCentral and ConnectWise to gain initial access, to run administrative command queries and to deploy the custom lateral movement and defacement script [victim_abbreviation]_fanout.sh.[6][1] |
|
| Enterprise | T1018 | Remote System Discovery |
ShinyHunters has enumerated the internal subnet using |
|
| Enterprise | T1593 | .003 | Search Open Websites/Domains: Code Repositories |
ShinyHunters has searched through target companies’ GitHub repositories for login credentials or API keys.[2] |
| Enterprise | T1684 | Social Engineering |
ShinyHunters has used social engineering to demand payment from victims.[5] |
|
| Enterprise | T1072 | Software Deployment Tools |
ShinyHunters has abused software deployment tools for lateral movement.[2] |
|
| Enterprise | T1528 | Steal Application Access Token |
ShinyHunters has stolen valid OAuth credentials from DevOps personnel or a company GitHub repository.[4] Additionally, ShinyHunters has stolen application access tokens to access cloud services and to bypass authentication mechanisms.[2] |
|
| Enterprise | T1195 | .001 | Supply Chain Compromise: Compromise Software Dependencies and Development Tools |
ShinyHunters has compromised CI/CD pipelines by gaining access to high privilege engineering accounts on Git version control, BrowserStack, JFrog and other cloud project management platforms.[1] |
| Enterprise | T1082 | System Information Discovery |
ShinyHunters has used the MeshCentral command-line utility meshctrl.js to collect hostnames and IDs of compromised systems.[6] |
|
| Enterprise | T1016 | System Network Configuration Discovery |
ShinyHunters has collected machine names and IP addresses by parsing the process scheduler configuration file psappsrv.cfg.[6] |
|
| Enterprise | T1552 | .001 | Unsecured Credentials: Credentials In Files |
ShinyHunters has gathered PII from database infrastructure.[4] |
| Enterprise | T1550 | .001 | Use Alternate Authentication Material: Application Access Token |
ShinyHunters has used stolen OAuth keys to access cloud infrastructure and to bypass two-factor authentication.[4] |
| Enterprise | T1078 | Valid Accounts |
ShinyHunters has used valid high-privileged SSO users as leverage during negotiations.[1] |
|
| .002 | Domain Accounts |
ShinyHunters has used valid domain accounts to gain initial access or to escalate privileges within environments.[2] |
||
| .004 | Cloud Accounts |
ShinyHunters has used valid cloud accounts to gain initial access or to escalate privileges within cloud environments.[2] Additionally, ShinyHunters has also used valid credentials from public repositories to include access keys to gain access to the victim organization’s AWS environment.[3][4] |
||
| ID | Name | References | Techniques |
|---|---|---|---|
| S0183 | Tor | ShinyHunters has used Tor for their DLS.[5] | Encrypted Channel: Asymmetric Cryptography, Proxy: Multi-hop Proxy |