ShinyHunters

ShinyHunters is a cyber criminal collective that has been active since at least 2019 operating under the ShinyCorp persona. ShinyHunters has targeted multiple industries and geographic regions gathering legitimate credentials and personally identifiable information (PII) for resale or extortion of victims. ShinyHunters has been associated with the broader collective called The Community, also known as The Com whose members have also included Scattered Spider and LAPSUS$. Public reporting has mentioned a variety of names for operations ShinyHunters members have reportedly conducted with members of other groups, including "Scattered Lapsus Hunters," "Scattered Lapsus Shiny Hunters," and "SLSH."[1][2][3][4][5][6][7][8]

ID: G1057
Associated Groups: UNC6240, Bling Libra
Version: 1.0
Created: 29 July 2026
Last Modified: 31 July 2026

Associated Group Descriptions

Name Description
UNC6240

[7][6]

Bling Libra

[3]

Techniques Used

Domain ID Name Use
Enterprise T1583 .001 Acquire Infrastructure: Domains

ShinyHunters has established clearnet and Tor data leak sites (DLS) including one named "SHINYHUNTERS" for the exfiltration and posting of stolen data.[7][5] Additionally, ShinyHunters has registered domains that mimic legitimate Microsoft Azure NetApp Files endpoints, such as azurenetfiles[.]net, and legitimate Okta SSO login pages, such as trial-6857053.okta[.]com.[6][1]

.004 Acquire Infrastructure: Server

ShinyHunters has used five IP addresses to host Python SimpleHTTP servers on port 8888, which exposed staging materials, customized agents, and .bash_history files.[6]

Enterprise T1595 .002 Active Scanning: Vulnerability Scanning

ShinyHunters has searched through victim companies’ GitHub repositories for vulnerabilities.[2]

Enterprise T1560 .002 Archive Collected Data: Archive via Library

ShinyHunters has used the following command to compress collected data: pv -s "$(du -sb exfil | awk '{print $1}')" | zstd -3 -T0 -o exfil.tar.zst.[6]

Enterprise T1110 Brute Force

ShinyHunters has performed brute force attacks against edge devices, such as VPNs or firewall solutions.[1]

Enterprise T1580 Cloud Infrastructure Discovery

ShinyHunters has used Amazon Simple Storage Service (S3) Browser and WinSCP to collect information on S3 bucket configurations.[3][2]  

Enterprise T1619 Cloud Storage Object Discovery

ShinyHunters has used Amazon Simple Storage Service (S3) Browser and WinSCP to access S3 objects.[3]

Enterprise T1059 .007 Command and Scripting Interpreter: JavaScript

ShinyHunters has used the MeshCentral command-line interface utility meshctrl.js and npm to interact with compromised systems. Specifically for npm, ShinyHunters has checked for the authenticode tool using the command npm list global authenticode.[6] Additionally, ShinyHunters has used the MeshCentral command to execute the propagation script: node meshctrl.js RunCommand --loginuser admin --loginpass '[password]' --id '[agent_id]' --run 'bash /tmp/[victim_abbreviation]_fanout.sh'.[6]

.009 Command and Scripting Interpreter: Cloud API

ShinyHunters has used the AWS Command Line Interface (CLI) for operations to include a variety of API calls, such as ListBuckets, CreateBucket and DeleteBucket.[3]

Enterprise T1485 Data Destruction

ShinyHunters has executed the DeleteBucket API call to delete buckets.[3]

Enterprise T1530 Data from Cloud Storage

ShinyHunters has collected data from insecure cloud buckets.[2]

Enterprise T1213 .003 Data from Information Repositories: Code Repositories

ShinyHunters has gathered information from and has searched for vulnerabilities in the target company’s GitHub repository source code.[4]

.006 Data from Information Repositories: Databases

ShinyHunters has collected Salesforce datasets from victims in the airline and retail sectors.[1]

Enterprise T1491 .001 Defacement: Internal Defacement

ShinyHunters has left ransom notes titled README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT.[6]

Enterprise T1587 .004 Develop Capabilities: Exploits

ShinyHunters has exploited zero-day vulnerability CVE-2026-35273 against Oracle PeopleSoft application infrastructure.[6]

Enterprise T1573 .002 Encrypted Channel: Asymmetric Cryptography

ShinyHunters has established a connection between the staging host and the C2 using SSH.[6]

Enterprise T1585 .002 Establish Accounts: Email Accounts

ShinyHunters has established multiple email accounts, such as shinycorp@tutonota[.]com, for use in extortion activities.[8][3]

Enterprise T1567 Exfiltration Over Web Service

ShinyHunters has used compromised Salesforce CRM (Customer Relationship Management) dashboards to exfiltrate bulk data. Additionally, ShinyHunters has used LimeWire, a file-sharing service, to showcase samples of stolen data.[1]

Enterprise T1190 Exploit Public-Facing Application

ShinyHunters has exploited CVE-2026-35273 against Oracle PeopleSoft application infrastructure.[6] ShinyHunters has exploited known vulnerabilities in internet-facing servers.[1]

Enterprise T1203 Exploitation for Client Execution

ShinyHunters has exploited vulnerabilities in the target company’s GitHub repository source code to enable more complex follow-on third-party or supply chain attacks.[4]

Enterprise T1210 Exploitation of Remote Services

ShinyHunters has exploited vulnerabilities in remote services for lateral movement.[2]

Enterprise T1083 File and Directory Discovery

ShinyHunters has checked mount points for Oracle PeopleSoft configurations and has checked the process scheduler configuration file psappsrv.cfg. Additionally, ShinyHunters has read WebLogic server XML configurations files (config.xml).[6]

Enterprise T1657 Financial Theft

ShinyHunters has called or sent text messages or emails to employees of victim organizations to demand payment in Bitcoin within 72 hours. Email addresses used in extortion activities include shinycorp@tuta[.]com, shinygroup@tuta[.]com, shinycorp@tutanota[.]com, and shinygroup@onionmail[.]com.[8][7][5][4][3][2][1]

Enterprise T1589 .001 Gather Victim Identity Information: Credentials

ShinyHunters has collected credentials containing PII, ultimately selling the information on their DLS.[4][3]

Enterprise T1105 Ingress Tool Transfer

ShinyHunters has deployed custom scripts to targeted systems from customized MeshAgents in their staging environment.[6]

Enterprise T1036 .005 Masquerading: Match Legitimate Resource Name or Location

ShinyHunters has disguised MeshCentral agent binaries as Microsoft Azure services, e.g. meshagent32-azure-ops.exe, meshagent64-azure-ops.exe, and meshagent64-v2.exe.[6]

Enterprise T1588 .002 Obtain Capabilities: Tool

ShinyHunters has obtained MeshCentral to deploy agents masquerading as legitimate cloud endpoints.[6] ShinyHunters has obtained WinSCP to gather information on S3 bucket configurations.[3] ShinyHunters has obtained ConnectWise and other RMM tools to gain initial access.[1]

.007 Obtain Capabilities: Artificial Intelligence

ShinyHunters has used Bland AI to create conversational pathways tailored to specific scenarios during voice phishing attacks.[1]

Enterprise T1069 .003 Permission Groups Discovery: Cloud Groups

ShinyHunters has executed API calls to enumerate permissions for compromised AWS accounts.[3]

Enterprise T1598 Phishing for Information

ShinyHunters has sent phishing emails to Microsoft Office 365 corporate users in order to steal credentials.[4]

.003 Spearphishing Link

ShinyHunters has used spearphishing emails with malicious links to gain initial access and credentials.[2]

Enterprise T1090 .003 Proxy: Multi-hop Proxy

ShinyHunters has used Tor to host their DLS.[5]

Enterprise T1219 Remote Access Tools

ShinyHunters has used MeshCentral and ConnectWise to gain initial access, to run administrative command queries and to deploy the custom lateral movement and defacement script [victim_abbreviation]_fanout.sh.[6][1]

Enterprise T1018 Remote System Discovery

ShinyHunters has enumerated the internal subnet using cat /etc/hosts | grep -E "[redacted_victim_string]".[6]

Enterprise T1593 .003 Search Open Websites/Domains: Code Repositories

ShinyHunters has searched through target companies’ GitHub repositories for login credentials or API keys.[2]

Enterprise T1684 Social Engineering

ShinyHunters has used social engineering to demand payment from victims.[5]

Enterprise T1072 Software Deployment Tools

ShinyHunters has abused software deployment tools for lateral movement.[2]

Enterprise T1528 Steal Application Access Token

ShinyHunters has stolen valid OAuth credentials from DevOps personnel or a company GitHub repository.[4] Additionally, ShinyHunters has stolen application access tokens to access cloud services and to bypass authentication mechanisms.[2]

Enterprise T1195 .001 Supply Chain Compromise: Compromise Software Dependencies and Development Tools

ShinyHunters has compromised CI/CD pipelines by gaining access to high privilege engineering accounts on Git version control, BrowserStack, JFrog and other cloud project management platforms.[1]

Enterprise T1082 System Information Discovery

ShinyHunters has used the MeshCentral command-line utility meshctrl.js to collect hostnames and IDs of compromised systems.[6]

Enterprise T1016 System Network Configuration Discovery

ShinyHunters has collected machine names and IP addresses by parsing the process scheduler configuration file psappsrv.cfg.[6]

Enterprise T1552 .001 Unsecured Credentials: Credentials In Files

ShinyHunters has gathered PII from database infrastructure.[4]

Enterprise T1550 .001 Use Alternate Authentication Material: Application Access Token

ShinyHunters has used stolen OAuth keys to access cloud infrastructure and to bypass two-factor authentication.[4]

Enterprise T1078 Valid Accounts

ShinyHunters has used valid high-privileged SSO users as leverage during negotiations.[1]

.002 Domain Accounts

ShinyHunters has used valid domain accounts to gain initial access or to escalate privileges within environments.[2]

.004 Cloud Accounts

ShinyHunters has used valid cloud accounts to gain initial access or to escalate privileges within cloud environments.[2] Additionally, ShinyHunters has also used valid credentials from public repositories to include access keys to gain access to the victim organization’s AWS environment.[3][4]

Software

ID Name References Techniques
S0183 Tor ShinyHunters has used Tor for their DLS.[5] Encrypted Channel: Asymmetric Cryptography, Proxy: Multi-hop Proxy

References