Threat group.View on attack.mitre.org
ShinyHunters is a cyber criminal collective that has been active since at least 2019 operating under the ShinyCorp persona. ShinyHunters has targeted multiple industries and geographic regions gathering legitimate credentials and personally identifiable information (PII) for resale or extortion of victims. ShinyHunters has been associated with the broader collective called The Community, also known as The Com whose members have also included Scattered Spider and LAPSUS$. Public reporting has mentioned a variety of names for operations ShinyHunters members have reportedly conducted with members of other groups, including “Scattered Lapsus Hunters,” “Scattered Lapsus Shiny Hunters,” and “SLSH.”
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
ShinyHunters has collected machine names and IP addresses by parsing the process scheduler configuration file psappsrv.cfg. |
| T1018 Remote System Discovery |
ShinyHunters has enumerated the internal subnet using ` cat /etc/hosts | grep -E "[redacted_victim_string]"`. |
| T1036.005 Match Legitimate Resource Name or Location |
ShinyHunters has disguised MeshCentral agent binaries as Microsoft Azure services, e.g. meshagent32-azure-ops.exe, meshagent64-azure-ops.exe, and meshagent64-v2.exe. |
| T1059.007 JavaScript |
ShinyHunters has used the MeshCentral command-line interface utility meshctrl.js and npm to interact with compromised systems. Specifically for npm, ShinyHunters has checked for the authenticode tool using the command `npm list global authenticode`. Additionally, ShinyHunters has used the MeshCentral command to execute the propagation script: ` node meshctrl.js RunCommand --loginuser admin --loginpass '[password]' --id '[agent_id]' --run 'bash /tmp/[victim_abbreviation]_fanout.sh' `. |
| T1059.009 Cloud API |
ShinyHunters has used the AWS Command Line Interface (CLI) for operations to include a variety of API calls, such as `ListBuckets`, `CreateBucket` and `DeleteBucket`. |
| T1069.003 Cloud Groups |
ShinyHunters has executed API calls to enumerate permissions for compromised AWS accounts. |
| T1072 Software Deployment Tools |
ShinyHunters has abused software deployment tools for lateral movement. |
| T1078 Valid Accounts |
ShinyHunters has used valid high-privileged SSO users as leverage during negotiations. |
| T1078.002 Domain Accounts |
ShinyHunters has used valid domain accounts to gain initial access or to escalate privileges within environments. |
| T1078.004 Cloud Accounts |
ShinyHunters has used valid cloud accounts to gain initial access or to escalate privileges within cloud environments. Additionally, ShinyHunters has also used valid credentials from public repositories to include access keys to gain access to the victim organization’s AWS environment. |
| T1082 System Information Discovery |
ShinyHunters has used the MeshCentral command-line utility meshctrl.js to collect hostnames and IDs of compromised systems. |
| T1083 File and Directory Discovery |
ShinyHunters has checked mount points for Oracle PeopleSoft configurations and has checked the process scheduler configuration file psappsrv.cfg. Additionally, ShinyHunters has read WebLogic server XML configurations files (config.xml). |
| T1090.003 Multi-hop Proxy |
ShinyHunters has used Tor to host their DLS. |
| T1105 Ingress Tool Transfer |
ShinyHunters has deployed custom scripts to targeted systems from customized MeshAgents in their staging environment. |
| T1110 Brute Force |
ShinyHunters has performed brute force attacks against edge devices, such as VPNs or firewall solutions. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.