Intel 471. (2021, August 23). Here’s how to guard your enterprise against ShinyHunters. Retrieved July 29, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1078.004 Cloud Accounts |
GroupShinyHunters | ShinyHunters has used valid cloud accounts to gain initial access or to escalate privileges within cloud environments. Additionally, ShinyHunters has also used valid credentials from public repositories to include access keys to gain access to the victim organization’s AWS environment. |
| T1203 Exploitation for Client Execution |
GroupShinyHunters | ShinyHunters has exploited vulnerabilities in the target company’s GitHub repository source code to enable more complex follow-on third-party or supply chain attacks. |
| T1213.003 Code Repositories |
GroupShinyHunters | ShinyHunters has gathered information from and has searched for vulnerabilities in the target company’s GitHub repository source code. |
| T1528 Steal Application Access Token |
GroupShinyHunters | ShinyHunters has stolen valid OAuth credentials from DevOps personnel or a company GitHub repository. Additionally, ShinyHunters has stolen application access tokens to access cloud services and to bypass authentication mechanisms. |
| T1550.001 Application Access Token |
GroupShinyHunters | ShinyHunters has used stolen OAuth keys to access cloud infrastructure and to bypass two-factor authentication. |
| T1552.001 Credentials In Files |
GroupShinyHunters | ShinyHunters has gathered PII from database infrastructure. |
| T1589.001 Credentials |
GroupShinyHunters | ShinyHunters has collected credentials containing PII, ultimately selling the information on their DLS. |
| T1598 Phishing for Information |
GroupShinyHunters | ShinyHunters has sent phishing emails to Microsoft Office 365 corporate users in order to steal credentials. |
| T1657 Financial Theft |
GroupShinyHunters | ShinyHunters has called or sent text messages or emails to employees of victim organizations to demand payment in Bitcoin within 72 hours. Email addresses used in extortion activities include shinycorp@tuta[.]com, shinygroup@tuta[.]com, shinycorp@tutanota[.]com, and shinygroup@onionmail[.]com. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.