ATT&CKReferencesElecticIQ Buyukkaya_ShinyHunters_Sept2025

ElecticIQ Buyukkaya_ShinyHunters_Sept2025

Büyükkaya, A. (2025, September 22). ShinyHunters Calling: Financially Motivated Data Extortion Group Targeting Enterprise Cloud Applications. Retrieved May 18, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1078
Valid Accounts
GroupShinyHunters

ShinyHunters has used valid high-privileged SSO users as leverage during negotiations.

T1110
Brute Force
GroupShinyHunters

ShinyHunters has performed brute force attacks against edge devices, such as VPNs or firewall solutions.

T1190
Exploit Public-Facing Application
GroupShinyHunters

ShinyHunters has exploited CVE-2026-35273 against Oracle PeopleSoft application infrastructure. ShinyHunters has exploited known vulnerabilities in internet-facing servers.

T1195.001
Compromise Software Dependencies and Development Tools
GroupShinyHunters

ShinyHunters has compromised CI/CD pipelines by gaining access to high privilege engineering accounts on Git version control, BrowserStack, JFrog and other cloud project management platforms.

T1213.006
Databases
GroupShinyHunters

ShinyHunters has collected Salesforce datasets from victims in the airline and retail sectors.

T1219
Remote Access Tools
GroupShinyHunters

ShinyHunters has used MeshCentral and ConnectWise to gain initial access, to run administrative command queries and to deploy the custom lateral movement and defacement script [victim_abbreviation]_fanout.sh.

T1567
Exfiltration Over Web Service
GroupShinyHunters

ShinyHunters has used compromised Salesforce CRM (Customer Relationship Management) dashboards to exfiltrate bulk data. Additionally, ShinyHunters has used LimeWire, a file-sharing service, to showcase samples of stolen data.

T1583.001
Domains
GroupShinyHunters

ShinyHunters has established clearnet and Tor data leak sites (DLS) including one named “SHINYHUNTERS” for the exfiltration and posting of stolen data. Additionally, ShinyHunters has registered domains that mimic legitimate Microsoft Azure NetApp Files endpoints, such as azurenetfiles[.]net, and legitimate Okta SSO login pages, such as trial-6857053.okta[.]com.

T1588.002
Tool
GroupShinyHunters

ShinyHunters has obtained MeshCentral to deploy agents masquerading as legitimate cloud endpoints. ShinyHunters has obtained WinSCP to gather information on S3 bucket configurations. ShinyHunters has obtained ConnectWise and other RMM tools to gain initial access.

T1588.007
Artificial Intelligence
GroupShinyHunters

ShinyHunters has used Bland AI to create conversational pathways tailored to specific scenarios during voice phishing attacks.

T1657
Financial Theft
GroupShinyHunters

ShinyHunters has called or sent text messages or emails to employees of victim organizations to demand payment in Bitcoin within 72 hours. Email addresses used in extortion activities include shinycorp@tuta[.]com, shinygroup@tuta[.]com, shinycorp@tutanota[.]com, and shinygroup@onionmail[.]com.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.