ATT&CKReferencesIntel471_SH_Aug2021

Intel471_SH_Aug2021

Intel 471. (2021, August 23). Here’s how to guard your enterprise against ShinyHunters. Retrieved July 29, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1078.004
Cloud Accounts
GroupShinyHunters

ShinyHunters has used valid cloud accounts to gain initial access or to escalate privileges within cloud environments. Additionally, ShinyHunters has also used valid credentials from public repositories to include access keys to gain access to the victim organization’s AWS environment.

T1203
Exploitation for Client Execution
GroupShinyHunters

ShinyHunters has exploited vulnerabilities in the target company’s GitHub repository source code to enable more complex follow-on third-party or supply chain attacks.

T1213.003
Code Repositories
GroupShinyHunters

ShinyHunters has gathered information from and has searched for vulnerabilities in the target company’s GitHub repository source code.

T1528
Steal Application Access Token
GroupShinyHunters

ShinyHunters has stolen valid OAuth credentials from DevOps personnel or a company GitHub repository. Additionally, ShinyHunters has stolen application access tokens to access cloud services and to bypass authentication mechanisms.

T1550.001
Application Access Token
GroupShinyHunters

ShinyHunters has used stolen OAuth keys to access cloud infrastructure and to bypass two-factor authentication.

T1552.001
Credentials In Files
GroupShinyHunters

ShinyHunters has gathered PII from database infrastructure.

T1589.001
Credentials
GroupShinyHunters

ShinyHunters has collected credentials containing PII, ultimately selling the information on their DLS.

T1598
Phishing for Information
GroupShinyHunters

ShinyHunters has sent phishing emails to Microsoft Office 365 corporate users in order to steal credentials.

T1657
Financial Theft
GroupShinyHunters

ShinyHunters has called or sent text messages or emails to employees of victim organizations to demand payment in Bitcoin within 72 hours. Email addresses used in extortion activities include shinycorp@tuta[.]com, shinygroup@tuta[.]com, shinycorp@tutanota[.]com, and shinygroup@onionmail[.]com.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.