Büyükkaya, A. (2025, September 22). ShinyHunters Calling: Financially Motivated Data Extortion Group Targeting Enterprise Cloud Applications. Retrieved May 18, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1078 Valid Accounts |
GroupShinyHunters | ShinyHunters has used valid high-privileged SSO users as leverage during negotiations. |
| T1110 Brute Force |
GroupShinyHunters | ShinyHunters has performed brute force attacks against edge devices, such as VPNs or firewall solutions. |
| T1190 Exploit Public-Facing Application |
GroupShinyHunters | ShinyHunters has exploited CVE-2026-35273 against Oracle PeopleSoft application infrastructure. ShinyHunters has exploited known vulnerabilities in internet-facing servers. |
| T1195.001 Compromise Software Dependencies and Development Tools |
GroupShinyHunters | ShinyHunters has compromised CI/CD pipelines by gaining access to high privilege engineering accounts on Git version control, BrowserStack, JFrog and other cloud project management platforms. |
| T1213.006 Databases |
GroupShinyHunters | ShinyHunters has collected Salesforce datasets from victims in the airline and retail sectors. |
| T1219 Remote Access Tools |
GroupShinyHunters | ShinyHunters has used MeshCentral and ConnectWise to gain initial access, to run administrative command queries and to deploy the custom lateral movement and defacement script [victim_abbreviation]_fanout.sh. |
| T1567 Exfiltration Over Web Service |
GroupShinyHunters | ShinyHunters has used compromised Salesforce CRM (Customer Relationship Management) dashboards to exfiltrate bulk data. Additionally, ShinyHunters has used LimeWire, a file-sharing service, to showcase samples of stolen data. |
| T1583.001 Domains |
GroupShinyHunters | ShinyHunters has established clearnet and Tor data leak sites (DLS) including one named “SHINYHUNTERS” for the exfiltration and posting of stolen data. Additionally, ShinyHunters has registered domains that mimic legitimate Microsoft Azure NetApp Files endpoints, such as azurenetfiles[.]net, and legitimate Okta SSO login pages, such as trial-6857053.okta[.]com. |
| T1588.002 Tool |
GroupShinyHunters | ShinyHunters has obtained MeshCentral to deploy agents masquerading as legitimate cloud endpoints. ShinyHunters has obtained WinSCP to gather information on S3 bucket configurations. ShinyHunters has obtained ConnectWise and other RMM tools to gain initial access. |
| T1588.007 Artificial Intelligence |
GroupShinyHunters | ShinyHunters has used Bland AI to create conversational pathways tailored to specific scenarios during voice phishing attacks. |
| T1657 Financial Theft |
GroupShinyHunters | ShinyHunters has called or sent text messages or emails to employees of victim organizations to demand payment in Bitcoin within 72 hours. Email addresses used in extortion activities include shinycorp@tuta[.]com, shinygroup@tuta[.]com, shinycorp@tutanota[.]com, and shinygroup@onionmail[.]com. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.