ATT&CKGroupsShinyHunters

ShinyHunters

G1057

Threat group.View on attack.mitre.org

About this group

ShinyHunters is a cyber criminal collective that has been active since at least 2019 operating under the ShinyCorp persona. ShinyHunters has targeted multiple industries and geographic regions gathering legitimate credentials and personally identifiable information (PII) for resale or extortion of victims. ShinyHunters has been associated with the broader collective called The Community, also known as The Com whose members have also included Scattered Spider and LAPSUS$. Public reporting has mentioned a variety of names for operations ShinyHunters members have reportedly conducted with members of other groups, including “Scattered Lapsus Hunters,” “Scattered Lapsus Shiny Hunters,” and “SLSH.”

Techniques used46

Procedure examples46

TechniqueProcedure example
T1016
System Network Configuration Discovery

ShinyHunters has collected machine names and IP addresses by parsing the process scheduler configuration file psappsrv.cfg.

T1018
Remote System Discovery

ShinyHunters has enumerated the internal subnet using ` cat /etc/hosts | grep -E "[redacted_victim_string]"`.

T1036.005
Match Legitimate Resource Name or Location

ShinyHunters has disguised MeshCentral agent binaries as Microsoft Azure services, e.g. meshagent32-azure-ops.exe, meshagent64-azure-ops.exe, and meshagent64-v2.exe.

T1059.007
JavaScript

ShinyHunters has used the MeshCentral command-line interface utility meshctrl.js and npm to interact with compromised systems. Specifically for npm, ShinyHunters has checked for the authenticode tool using the command `npm list global authenticode`. Additionally, ShinyHunters has used the MeshCentral command to execute the propagation script: ` node meshctrl.js RunCommand --loginuser admin --loginpass '[password]' --id '[agent_id]' --run 'bash /tmp/[victim_abbreviation]_fanout.sh' `.

T1059.009
Cloud API

ShinyHunters has used the AWS Command Line Interface (CLI) for operations to include a variety of API calls, such as `ListBuckets`, `CreateBucket` and `DeleteBucket`.

T1069.003
Cloud Groups

ShinyHunters has executed API calls to enumerate permissions for compromised AWS accounts.

T1072
Software Deployment Tools

ShinyHunters has abused software deployment tools for lateral movement.

T1078
Valid Accounts

ShinyHunters has used valid high-privileged SSO users as leverage during negotiations.

T1078.002
Domain Accounts

ShinyHunters has used valid domain accounts to gain initial access or to escalate privileges within environments.

T1078.004
Cloud Accounts

ShinyHunters has used valid cloud accounts to gain initial access or to escalate privileges within cloud environments. Additionally, ShinyHunters has also used valid credentials from public repositories to include access keys to gain access to the victim organization’s AWS environment.

T1082
System Information Discovery

ShinyHunters has used the MeshCentral command-line utility meshctrl.js to collect hostnames and IDs of compromised systems.

T1083
File and Directory Discovery

ShinyHunters has checked mount points for Oracle PeopleSoft configurations and has checked the process scheduler configuration file psappsrv.cfg. Additionally, ShinyHunters has read WebLogic server XML configurations files (config.xml).

T1090.003
Multi-hop Proxy

ShinyHunters has used Tor to host their DLS.

T1105
Ingress Tool Transfer

ShinyHunters has deployed custom scripts to targeted systems from customized MeshAgents in their staging environment.

T1110
Brute Force

ShinyHunters has performed brute force attacks against edge devices, such as VPNs or firewall solutions.

View all 46 procedure examples

Software1

Campaigns0

None recorded.

References8

  1. ElecticIQ Buyukkaya_ShinyHunters_Sept2025 Open source
    Büyükkaya, A. (2025, September 22). ShinyHunters Calling: Financially Motivated Data Extortion Group Targeting Enterprise Cloud Applications. Retrieved May 18, 2026.
  2. FBI_SHLMS_May2026 Open source
    Federal Bureau of Investigation. (2026, May 15). ShinyHunters: Cyber Criminal Group Attacks Learning Management System. Retrieved July 1, 2026.
  3. Google Salesforce JUN 2025 Open source
    Google Threat Intelligence Group. (2025, June 4). The Cost of a Call: From Voice Phishing to Data Extortion. Retrieved October 22, 2025.
  4. Google_SHOracle_Jun2026 Open source
    Mandiant, Google Threat Intelligence Group. (2026, June 11). ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit. Retrieved June 11, 2026.
  5. Intel471_SH_Aug2021 Open source
    Intel 471. (2021, August 23). Here’s how to guard your enterprise against ShinyHunters. Retrieved July 29, 2026.
  6. Mandiant_SHDataTheft_Jan2026 Open source
    Mandiant. (2026, January 30). Vishing for Access: Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft. Retrieved June 16, 2026.
  7. SOCRadar_ShinyHunters_Mar2024 Open source
    SOCRadar. (2024, March 18). Dark Web Profile: ShinyHunters. Retrieved May 18, 2026.
  8. Unit42KelleyVaya_BlingLibra_Aug2024 Open source
    Kelley, M., Vaya, C. (2024, August 23). Bling Libra’s Tactical Evolution: The Threat Actor Group Behind ShinyHunters Ransomware. Retrieved May 18, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.