{"description": "Enterprise techniques used by Mini Shai-Hulud, ATT&CK software S9043 (v1.0)", "name": "Mini Shai-Hulud (S9043)", "domain": "enterprise-attack", "versions": {"layer": "4.5", "attack": "19", "navigator": "5.3.2"}, "techniques": [{"techniqueID": "T1087", "showSubtechniques": true}, {"techniqueID": "T1087.004", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has enumerated cloud accounts and subscriptions accessible to the targeted identity.(Citation: Hunt.io TeamPCP Toolkit MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1071", "showSubtechniques": true}, {"techniqueID": "T1071.001", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has has exfiltrated data through the use of HTTPS POST requests to C2 domains.(Citation: Trend Micro TeamPCP MAY 2026)(Citation: Flashpoint Mini Shai-Hulud MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1560", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has compressed collected credentials to reduce transmission size and to make string content harder to detect in memory forensics captures.(Citation: Hunt.io TeamPCP Toolkit MAY 2026)", "score": 1, "showSubtechniques": true}, {"techniqueID": "T1560.001", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has compressed collected credentials and data within tar archive files prior to exfiltration.(Citation: Trend Micro TeamPCP MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1119", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has the ability to automatically compile gathered credentials from configuration files and password vaults within an archive and exfiltrate stolen data leveraging both a primary and fallback C2.(Citation: Flashpoint Mini Shai-Hulud MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1059", "showSubtechniques": true}, {"techniqueID": "T1059.006", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has utilized Python scripts to execute payloads.(Citation: Wiz Mini Shai-Hulud MAY 2026)(Citation: Phoenix TeamPCP 20 MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1059.007", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has leveraged JavaScript runtime to execute malicious scripts.(Citation: Trend Micro TeamPCP MAY 2026)(Citation: Flashpoint Mini Shai-Hulud MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1059.013", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has utilized the Docker command-line tool to gather details of the victim environment and collect credentials.(Citation: Hunt.io TeamPCP Toolkit MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1554", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043)  has established persistence through modifying software binaries to include AI coding agents\u2019 configuration or setting files that act as hooks, tasks or execution triggers.(Citation: Flashpoint Mini Shai-Hulud MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1609", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has utilized container administration commands to gather details of compromised hosts and gather credentials to include Kubernetes command-line utilities `kubectl get secrets`.(Citation: Trend Micro TeamPCP MAY 2026)(Citation: Phoenix TeamPCP 20 MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1543", "showSubtechniques": true}, {"techniqueID": "T1543.001", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has established persistence on macOS hosts by installing a gh-token-monitor daemon through LaunchAgent that polls GitHub every 60 seconds.(Citation: Wiz Mini Shai-Hulud MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1543.002", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has created  .service files using Systemd on victim Linux hosts to establish persistence.(Citation: Wiz Mini Shai-Hulud MAY 2026)(Citation: Hunt.io TeamPCP Toolkit MAY 2026)(Citation: Flashpoint Mini Shai-Hulud MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1555", "showSubtechniques": true}, {"techniqueID": "T1555.005", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has gathered credentials stored in password managers to include password vaults.(Citation: Wiz Mini Shai-Hulud MAY 2026)(Citation: Hunt.io TeamPCP Toolkit MAY 2026)(Citation: Phoenix TeamPCP 20 MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1555.006", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has captured credentials stored in cloud secret stores.(Citation: Wiz Mini Shai-Hulud MAY 2026)(Citation: Trend Micro TeamPCP MAY 2026)(Citation: Hunt.io TeamPCP Toolkit MAY 2026)(Citation: Phoenix TeamPCP 20 MAY 2026)(Citation: Flashpoint Mini Shai-Hulud MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1485", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has wiped data on devices that fall within specified parameters to include those that resolve to specific geolocations including Iran and Israel.(Citation: Hunt.io TeamPCP Toolkit MAY 2026)(Citation: Phoenix TeamPCP 20 MAY 2026) [Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has also implemented a dead-man\u2019s switch that wipes the victims home directory if the operator revokes a GitHub token created by the adversary. (Citation: Flashpoint Mini Shai-Hulud MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1132", "showSubtechniques": true}, {"techniqueID": "T1132.001", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has used base64 encoding to obfuscate URLs used for C2.(Citation: Hunt.io TeamPCP Toolkit MAY 2026)(Citation: Phoenix TeamPCP 20 MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1213", "showSubtechniques": true}, {"techniqueID": "T1213.003", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has gathered and downloaded data stored on both compromised and publicly accessible code repositories.(Citation: Phoenix TeamPCP 20 MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1140", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has the ability to decrypt obfuscated payloads.(Citation: Trend Micro TeamPCP MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1546", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has modified settings and configuration files of AI coding agents and other coding applications in order to create event triggered executions through creating hooks and runOn conditions.(Citation: Flashpoint Mini Shai-Hulud MAY 2026)", "score": 1, "showSubtechniques": true}, {"techniqueID": "T1546.018", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has utilized Python startup hooks to include the .pth import mechanism for execution.(Citation: Trend Micro TeamPCP MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1480", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has utilized execution guardrails in order to prevent operating in restricted geolocations to include Russia by checking the devices language and terminating when a forbidden value is detected.(Citation: Wiz Mini Shai-Hulud MAY 2026)(Citation: Phoenix TeamPCP 20 MAY 2026) [Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has also utilized designated instructions that execute when victim hosts match geolocations to include wiping victim devices when the device is determined to be located within Iran or Israel.(Citation: Hunt.io TeamPCP Toolkit MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1041", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has exfiltrated encrypted archives over C2 domains.(Citation: Trend Micro TeamPCP MAY 2026)(Citation: Hunt.io TeamPCP Toolkit MAY 2026)(Citation: Phoenix TeamPCP 20 MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1567", "showSubtechniques": true}, {"techniqueID": "T1567.001", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has exfiltrated data through the use of the victim\u2019s own GitHub repository by creating a new public repository using a unique naming convention from a curated list of key words or themes.(Citation: Trend Micro TeamPCP MAY 2026)(Citation: Hunt.io TeamPCP Toolkit MAY 2026)(Citation: Phoenix TeamPCP 20 MAY 2026)(Citation: Flashpoint Mini Shai-Hulud MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1008", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has established Fallback Channels to exfiltrate data to Github when other configured infrastructure is found to be unreachable.(Citation: Wiz Mini Shai-Hulud MAY 2026)(Citation: Trend Micro TeamPCP MAY 2026)(Citation: Hunt.io TeamPCP Toolkit MAY 2026)(Citation: Phoenix TeamPCP 20 MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1083", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has enumerated home directories, file paths and files associated with storing or containing credentials and other secrets.(Citation: Hunt.io TeamPCP Toolkit MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1564", "showSubtechniques": true}, {"techniqueID": "T1564.011", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has suppressed output so that nothing is printed to terminal and has utilized silent exiting when environmental variables match restricted values.(Citation: Hunt.io TeamPCP Toolkit MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1070", "showSubtechniques": true}, {"techniqueID": "T1070.004", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has deleted all artifacts to include gathered credential archives to reduce disk persistence and detection.(Citation: Trend Micro TeamPCP MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1105", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has the ability to download additional payloads from adversary controlled or compromised infrastructure.(Citation: Wiz Mini Shai-Hulud MAY 2026)(Citation: Hunt.io TeamPCP Toolkit MAY 2026)(Citation: Phoenix TeamPCP 20 MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1559", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has executed via the use of `subprocess.run` and fed input through standard input `stdin` which acted as a pipe to send data from the parent process and the child process `sys.executable` within memory.(Citation: Trend Micro TeamPCP MAY 2026)(Citation: Hunt.io TeamPCP Toolkit MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1036", "showSubtechniques": true}, {"techniqueID": "T1036.005", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has leveraged a user-agent string that mimics a standard git client to avoid detection within network logs.(Citation: Hunt.io TeamPCP Toolkit MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1027", "showSubtechniques": true}, {"techniqueID": "T1027.013", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has used a hybrid AES-256-GCM and RSA OAEP-SHA256 encryption to archive gathered data. [Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has also utilized custom MD5-keystream XOR cipher to encrypt data.(Citation: Trend Micro TeamPCP MAY 2026) [Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has also been deployed via an obfuscated script using Bun JavaScript runtime.(Citation: Flashpoint Mini Shai-Hulud MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1003", "showSubtechniques": true}, {"techniqueID": "T1003.007", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has scraped runner process memory to extract short-lived identity tokens, which it then exchanged for per-package npm trusted-publisher tokens.(Citation: Flashpoint Mini Shai-Hulud MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1677", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has utilized Github Actions to propagate through the use of triggered workflows.(Citation: Wiz Mini Shai-Hulud MAY 2026)(Citation: Phoenix TeamPCP 20 MAY 2026)(Citation: Flashpoint Mini Shai-Hulud MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1090", "showSubtechniques": true}, {"techniqueID": "T1090.003", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has the ability to exfiltrate stolen credentials via the Session messenger network.(Citation: Wiz Mini Shai-Hulud MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1021", "showSubtechniques": true}, {"techniqueID": "T1021.007", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has accessed and propagated to AWS EC2 instances via SSM Send-Command.(Citation: Phoenix TeamPCP 20 MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1053", "showSubtechniques": true}, {"techniqueID": "T1053.006", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has obtained persistence on Linux devices by writing the `gh-token-monitor` daemon within `~/.config/systemd/user/gh-token-monitor.service` that polls GitHub every 60 seconds.(Citation: Wiz Mini Shai-Hulud MAY 2026) [Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has also leveraged a daemon called \u201ckitty-monitor.service\u201d to maintain persistence within Linux hosts.(Citation: Flashpoint Mini Shai-Hulud MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1528", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has stolen application access tokens and other tokens to include those associated with CI/CD.(Citation: Wiz Mini Shai-Hulud MAY 2026)(Citation: Trend Micro TeamPCP MAY 2026)(Citation: Hunt.io TeamPCP Toolkit MAY 2026)(Citation: Phoenix TeamPCP 20 MAY 2026)(Citation: Flashpoint Mini Shai-Hulud MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1649", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has collected victim client certificates to assist in signed authentication assertion with Azure environments.(Citation: Hunt.io TeamPCP Toolkit MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1195", "showSubtechniques": true}, {"techniqueID": "T1195.001", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has published itself on compromised victim code repositories to propagate malicious versions of packages to other victims.(Citation: Trend Micro TeamPCP MAY 2026)(Citation: Flashpoint Mini Shai-Hulud MAY 2026)(Citation: Flashpoint Mini Shai-Hulud MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1082", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has gathered system information of victim hosts through the use of common discovery commands to include `hostname`, `uname-a` and `printenv`.(Citation: Trend Micro TeamPCP MAY 2026) [Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has also conducted system checks of the victim device to include enumerating the system type and the number of CPUs operating on victim host.(Citation: Hunt.io TeamPCP Toolkit MAY 2026)(Citation: Phoenix TeamPCP 20 MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1614", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has discovered the compromised systems location through a query of the system timezone configuration and the locale settings.(Citation: Hunt.io TeamPCP Toolkit MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1614.001", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has the ability to check system details for its language configuration and terminates actions when the system is configured for the Russian language.(Citation: Wiz Mini Shai-Hulud MAY 2026)(Citation: Phoenix TeamPCP 20 MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1016", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has discovered network configuration through the use of system commands to include `ip addr`, and `ip route`.(Citation: Trend Micro TeamPCP MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1033", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has leveraged commands such as `whoami` to identify the system owner.(Citation: Trend Micro TeamPCP MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1124", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has queried the system timezone configuration and timezone data files to include `/etc/localtime`, and locale settings to determine the geolocation of the compromised host.(Citation: Hunt.io TeamPCP Toolkit MAY 2026)(Citation: Phoenix TeamPCP 20 MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1205", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has examined commit messages for a keyword followed by base64 encoded segments to validate communications and to execute subsequent actions to include exfiltration.(Citation: Hunt.io TeamPCP Toolkit MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1552", "showSubtechniques": true}, {"techniqueID": "T1552.001", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has collected credentials stored within configuration files.(Citation: Trend Micro TeamPCP MAY 2026)(Citation: Phoenix TeamPCP 20 MAY 2026) [Mini Shai-Hulud](https://attack.mitre.org/software/S9043)  has also gathered credentials from files stored in common credential file paths to include targeting git-credentials, azureProfile.json, and application_default_credentials.json.(Citation: Hunt.io TeamPCP Toolkit MAY 2026)(Citation: Flashpoint Mini Shai-Hulud MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1552.004", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has gathered unsecured credentials to include SSH private keys within .ssh.(Citation: Trend Micro TeamPCP MAY 2026)(Citation: Hunt.io TeamPCP Toolkit MAY 2026)(Citation: Flashpoint Mini Shai-Hulud MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1552.005", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has gathered credentials and secrets from AWS, Google Cloud Platform (GCP) and Azure metadata API.(Citation: Hunt.io TeamPCP Toolkit MAY 2026)(Citation: Flashpoint Mini Shai-Hulud MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1552.007", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has gathered unsecured API keys stored in container orchestrators.(Citation: Hunt.io TeamPCP Toolkit MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1550", "showSubtechniques": true}, {"techniqueID": "T1550.001", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has the ability to authenticate using stolen application access tokens.(Citation: Wiz Mini Shai-Hulud MAY 2026)(Citation: Phoenix TeamPCP 20 MAY 2026)(Citation: Flashpoint Mini Shai-Hulud MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1078", "showSubtechniques": true}, {"techniqueID": "T1078.004", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has used compromised accounts for Docker Hub and GitHub to publish malicious software packages.(Citation: Trend Micro TeamPCP MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1497", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has evaded sandbox detection by applying a 1-in-6 probability gate that generates a random number which will only trigger the wiper functionality when the set number outcome is met even in environments that match parameters of a geopolitical target.(Citation: Hunt.io TeamPCP Toolkit MAY 2026)", "score": 1, "showSubtechniques": true}, {"techniqueID": "T1497.001", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has evaded execution in virtual environments and sandboxes through checking system information to include the number of CPUs and exiting at times when there were less than four and other times when there were less than two CPUs.(Citation: Wiz Mini Shai-Hulud MAY 2026)(Citation: Hunt.io TeamPCP Toolkit MAY 2026)(Citation: Phoenix TeamPCP 20 MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1102", "showSubtechniques": true}, {"techniqueID": "T1102.001", "comment": "[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has leveraged GitHub commit-search API to recover fallback C2 domains stored in auto-created public Github repositories.(Citation: Wiz Mini Shai-Hulud MAY 2026)(Citation: Trend Micro TeamPCP MAY 2026)(Citation: Hunt.io TeamPCP Toolkit MAY 2026)(Citation: Phoenix TeamPCP 20 MAY 2026)(Citation: Flashpoint Mini Shai-Hulud MAY 2026)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}], "gradient": {"colors": ["#ffffff", "#66b1ff"], "minValue": 0, "maxValue": 1}, "legendItems": [{"label": "used by Mini Shai-Hulud", "color": "#66b1ff"}]}