{"description": "Enterprise techniques used by ShinyHunters, ATT&CK group G1057 (v1.0)", "name": "ShinyHunters (G1057)", "domain": "enterprise-attack", "versions": {"layer": "4.5", "attack": "19", "navigator": "5.3.2"}, "techniques": [{"techniqueID": "T1583", "showSubtechniques": true}, {"techniqueID": "T1583.001", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has established clearnet and Tor data leak sites (DLS) including one named \u201cSHINYHUNTERS\u201d for the exfiltration and posting of stolen data.(Citation: Mandiant_SHDataTheft_Jan2026)(Citation: FBI_SHLMS_May2026) Additionally, [ShinyHunters](https://attack.mitre.org/groups/G1057) has registered domains that mimic legitimate Microsoft Azure NetApp Files endpoints, such as azurenetfiles[.]net, and legitimate Okta SSO login pages, such as trial-6857053.okta[.]com.(Citation: Google_SHOracle_Jun2026)(Citation: ElecticIQ Buyukkaya_ShinyHunters_Sept2025)  ", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1583.004", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has used five IP addresses to host Python SimpleHTTP servers on port 8888, which exposed staging materials, customized agents, and .bash_history files.(Citation: Google_SHOracle_Jun2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1595", "showSubtechniques": true}, {"techniqueID": "T1595.002", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has searched through victim companies\u2019 GitHub repositories for vulnerabilities.(Citation: SOCRadar_ShinyHunters_Mar2024)   ", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1560", "showSubtechniques": true}, {"techniqueID": "T1560.002", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has used the following command to compress collected data: ` pv -s \"$(du -sb exfil | awk '{print $1}')\" | zstd -3 -T0 -o exfil.tar.zst `.(Citation: Google_SHOracle_Jun2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1110", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has performed brute force attacks against edge devices, such as VPNs or firewall solutions.(Citation: ElecticIQ Buyukkaya_ShinyHunters_Sept2025)   ", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1580", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has used Amazon Simple Storage Service (S3) Browser and WinSCP to collect information on S3 bucket configurations.(Citation: Unit42KelleyVaya_BlingLibra_Aug2024)(Citation: SOCRadar_ShinyHunters_Mar2024)\u00a0\u00a0", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1619", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has used Amazon Simple Storage Service (S3) Browser and WinSCP to access S3 objects.(Citation: Unit42KelleyVaya_BlingLibra_Aug2024)  ", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1059", "showSubtechniques": true}, {"techniqueID": "T1059.007", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has used the MeshCentral command-line interface utility meshctrl.js and npm to interact with compromised systems. Specifically for npm, [ShinyHunters](https://attack.mitre.org/groups/G1057) has checked for the authenticode tool using the command `npm list global authenticode`.(Citation: Google_SHOracle_Jun2026) Additionally, [ShinyHunters](https://attack.mitre.org/groups/G1057) has used the MeshCentral command to execute the propagation script: ` node meshctrl.js RunCommand --loginuser admin --loginpass '[password]' --id '[agent_id]' --run 'bash /tmp/[victim_abbreviation]_fanout.sh' `.(Citation: Google_SHOracle_Jun2026) ", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1059.009", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has used the AWS Command Line Interface (CLI) for operations to include a variety of API calls, such as `ListBuckets`, `CreateBucket` and `DeleteBucket`.(Citation: Unit42KelleyVaya_BlingLibra_Aug2024)   ", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1485", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has executed the `DeleteBucket` API call to delete buckets.(Citation: Unit42KelleyVaya_BlingLibra_Aug2024)   ", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1530", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has collected data from insecure cloud buckets.(Citation: SOCRadar_ShinyHunters_Mar2024)   ", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1213", "showSubtechniques": true}, {"techniqueID": "T1213.003", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has gathered information from and has searched for vulnerabilities in the target company\u2019s GitHub repository source code.(Citation: Intel471_SH_Aug2021)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1213.006", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has collected Salesforce datasets from victims in the airline and retail sectors.(Citation: ElecticIQ Buyukkaya_ShinyHunters_Sept2025)    ", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1491", "showSubtechniques": true}, {"techniqueID": "T1491.001", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has left ransom notes titled README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT.(Citation: Google_SHOracle_Jun2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1587", "showSubtechniques": true}, {"techniqueID": "T1587.004", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has exploited zero-day vulnerability CVE-2026-35273 against Oracle PeopleSoft application infrastructure.(Citation: Google_SHOracle_Jun2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1573", "showSubtechniques": true}, {"techniqueID": "T1573.002", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has established a connection between the staging host and the C2 using SSH.(Citation: Google_SHOracle_Jun2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1585", "showSubtechniques": true}, {"techniqueID": "T1585.002", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has established multiple email accounts, such as shinycorp@tutonota[.]com, for use in extortion activities.(Citation: Google Salesforce JUN 2025)(Citation: Unit42KelleyVaya_BlingLibra_Aug2024)   ", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1567", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has used compromised Salesforce CRM (Customer Relationship Management) dashboards to exfiltrate bulk data. Additionally, [ShinyHunters](https://attack.mitre.org/groups/G1057) has used LimeWire, a file-sharing service, to showcase samples of stolen data.(Citation: ElecticIQ Buyukkaya_ShinyHunters_Sept2025)   ", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1190", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has exploited CVE-2026-35273 against Oracle PeopleSoft application infrastructure.(Citation: Google_SHOracle_Jun2026) [ShinyHunters](https://attack.mitre.org/groups/G1057) has exploited known vulnerabilities in internet-facing servers.(Citation: ElecticIQ Buyukkaya_ShinyHunters_Sept2025)  ", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1203", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has exploited vulnerabilities in the target company\u2019s GitHub repository source code to enable more complex follow-on third-party or supply chain attacks.(Citation: Intel471_SH_Aug2021)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1210", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has exploited vulnerabilities in remote services for lateral movement.(Citation: SOCRadar_ShinyHunters_Mar2024)  ", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1083", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has checked mount points for Oracle PeopleSoft configurations and has checked the process scheduler configuration file psappsrv.cfg. Additionally, [ShinyHunters](https://attack.mitre.org/groups/G1057) has read WebLogic server XML configurations files (config.xml).(Citation: Google_SHOracle_Jun2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1657", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has called or sent text messages or emails to employees of victim organizations to demand payment in Bitcoin within 72 hours. Email addresses used in extortion activities include shinycorp@tuta[.]com, shinygroup@tuta[.]com, shinycorp@tutanota[.]com, and shinygroup@onionmail[.]com.(Citation: Google Salesforce JUN 2025)(Citation: Mandiant_SHDataTheft_Jan2026)(Citation: FBI_SHLMS_May2026)(Citation: Intel471_SH_Aug2021)(Citation: Unit42KelleyVaya_BlingLibra_Aug2024)(Citation: SOCRadar_ShinyHunters_Mar2024)(Citation: ElecticIQ Buyukkaya_ShinyHunters_Sept2025)  ", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1589", "showSubtechniques": true}, {"techniqueID": "T1589.001", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has collected credentials containing PII, ultimately selling the information on their DLS.(Citation: Intel471_SH_Aug2021)(Citation: Unit42KelleyVaya_BlingLibra_Aug2024) ", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1105", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has deployed custom scripts to targeted systems from customized MeshAgents in their staging environment.(Citation: Google_SHOracle_Jun2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1036", "showSubtechniques": true}, {"techniqueID": "T1036.005", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has disguised MeshCentral agent binaries as Microsoft Azure services, e.g. meshagent32-azure-ops.exe, meshagent64-azure-ops.exe, and meshagent64-v2.exe.(Citation: Google_SHOracle_Jun2026) ", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1588", "showSubtechniques": true}, {"techniqueID": "T1588.002", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has obtained MeshCentral to deploy agents masquerading as legitimate cloud endpoints.(Citation: Google_SHOracle_Jun2026) [ShinyHunters](https://attack.mitre.org/groups/G1057) has obtained WinSCP to gather information on S3 bucket configurations.(Citation: Unit42KelleyVaya_BlingLibra_Aug2024) [ShinyHunters](https://attack.mitre.org/groups/G1057) has obtained [ConnectWise](https://attack.mitre.org/software/S0591) and other RMM tools to gain initial access.(Citation: ElecticIQ Buyukkaya_ShinyHunters_Sept2025)       ", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1588.007", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has used Bland AI to create conversational pathways tailored to specific scenarios during voice phishing attacks.(Citation: ElecticIQ Buyukkaya_ShinyHunters_Sept2025)   ", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1069", "showSubtechniques": true}, {"techniqueID": "T1069.003", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has executed API calls to enumerate permissions for compromised AWS accounts.(Citation: Unit42KelleyVaya_BlingLibra_Aug2024)   ", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1598", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has sent phishing emails to Microsoft Office 365 corporate users in order to steal credentials.(Citation: Intel471_SH_Aug2021) ", "score": 1, "showSubtechniques": true}, {"techniqueID": "T1598.003", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has used spearphishing emails with malicious links to gain initial access and credentials.(Citation: SOCRadar_ShinyHunters_Mar2024)  ", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1090", "showSubtechniques": true}, {"techniqueID": "T1090.003", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has used [Tor](https://attack.mitre.org/software/S0183) to host their DLS.(Citation: FBI_SHLMS_May2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1219", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has used MeshCentral and [ConnectWise](https://attack.mitre.org/software/S0591) to gain initial access, to run administrative command queries and to deploy the custom lateral movement and defacement script [victim_abbreviation]_fanout.sh.(Citation: Google_SHOracle_Jun2026)(Citation: ElecticIQ Buyukkaya_ShinyHunters_Sept2025)   ", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1018", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has enumerated the internal subnet using ` cat /etc/hosts | grep -E \"[redacted_victim_string]\"`.(Citation: Google_SHOracle_Jun2026)    ", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1593", "showSubtechniques": true}, {"techniqueID": "T1593.003", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has searched through target companies\u2019 GitHub repositories for login credentials or API keys.(Citation: SOCRadar_ShinyHunters_Mar2024)   ", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1684", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has used social engineering to demand payment from victims.(Citation: FBI_SHLMS_May2026) ", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1072", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has abused software deployment tools for lateral movement.(Citation: SOCRadar_ShinyHunters_Mar2024)  ", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1528", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has stolen valid OAuth credentials from DevOps personnel or a company GitHub repository.(Citation: Intel471_SH_Aug2021) Additionally, [ShinyHunters](https://attack.mitre.org/groups/G1057) has stolen application access tokens to access cloud services and to bypass authentication mechanisms.(Citation: SOCRadar_ShinyHunters_Mar2024)   ", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1195", "showSubtechniques": true}, {"techniqueID": "T1195.001", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has compromised CI/CD pipelines by gaining access to high privilege engineering accounts on Git version control, BrowserStack, JFrog and other cloud project management platforms.(Citation: ElecticIQ Buyukkaya_ShinyHunters_Sept2025)   ", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1082", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has used the MeshCentral command-line utility meshctrl.js to collect hostnames and IDs of compromised systems.(Citation: Google_SHOracle_Jun2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1016", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has collected machine names and IP addresses by parsing the process scheduler configuration file psappsrv.cfg.(Citation: Google_SHOracle_Jun2026)    ", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1552", "showSubtechniques": true}, {"techniqueID": "T1552.001", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has gathered PII from database infrastructure.(Citation: Intel471_SH_Aug2021) ", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1550", "showSubtechniques": true}, {"techniqueID": "T1550.001", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has used stolen OAuth keys to access cloud infrastructure and to bypass two-factor authentication.(Citation: Intel471_SH_Aug2021) ", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1078", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has used valid high-privileged SSO users as leverage during negotiations.(Citation: ElecticIQ Buyukkaya_ShinyHunters_Sept2025)   ", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1078.002", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has used valid domain accounts to gain initial access or to escalate privileges within environments.(Citation: SOCRadar_ShinyHunters_Mar2024)  ", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1078.004", "comment": "[ShinyHunters](https://attack.mitre.org/groups/G1057) has used valid cloud accounts to gain initial access or to escalate privileges within cloud environments.(Citation: SOCRadar_ShinyHunters_Mar2024) Additionally, [ShinyHunters](https://attack.mitre.org/groups/G1057) has also used valid credentials from public repositories to include access keys to gain access to the victim organization\u2019s AWS environment.(Citation: Unit42KelleyVaya_BlingLibra_Aug2024)(Citation: Intel471_SH_Aug2021)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}], "gradient": {"colors": ["#ffffff", "#66b1ff"], "minValue": 0, "maxValue": 1}, "legendItems": [{"label": "used by ShinyHunters", "color": "#66b1ff"}]}