SOCRadar. (2024, March 18). Dark Web Profile: ShinyHunters. Retrieved May 18, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1072 Software Deployment Tools |
GroupShinyHunters | ShinyHunters has abused software deployment tools for lateral movement. |
| T1078.002 Domain Accounts |
GroupShinyHunters | ShinyHunters has used valid domain accounts to gain initial access or to escalate privileges within environments. |
| T1078.004 Cloud Accounts |
GroupShinyHunters | ShinyHunters has used valid cloud accounts to gain initial access or to escalate privileges within cloud environments. Additionally, ShinyHunters has also used valid credentials from public repositories to include access keys to gain access to the victim organization’s AWS environment. |
| T1210 Exploitation of Remote Services |
GroupShinyHunters | ShinyHunters has exploited vulnerabilities in remote services for lateral movement. |
| T1528 Steal Application Access Token |
GroupShinyHunters | ShinyHunters has stolen valid OAuth credentials from DevOps personnel or a company GitHub repository. Additionally, ShinyHunters has stolen application access tokens to access cloud services and to bypass authentication mechanisms. |
| T1530 Data from Cloud Storage |
GroupShinyHunters | ShinyHunters has collected data from insecure cloud buckets. |
| T1580 Cloud Infrastructure Discovery |
GroupShinyHunters | ShinyHunters has used Amazon Simple Storage Service (S3) Browser and WinSCP to collect information on S3 bucket configurations. |
| T1593.003 Code Repositories |
GroupShinyHunters | ShinyHunters has searched through target companies’ GitHub repositories for login credentials or API keys. |
| T1595.002 Vulnerability Scanning |
GroupShinyHunters | ShinyHunters has searched through victim companies’ GitHub repositories for vulnerabilities. |
| T1598.003 Spearphishing Link |
GroupShinyHunters | ShinyHunters has used spearphishing emails with malicious links to gain initial access and credentials. |
| T1657 Financial Theft |
GroupShinyHunters | ShinyHunters has called or sent text messages or emails to employees of victim organizations to demand payment in Bitcoin within 72 hours. Email addresses used in extortion activities include shinycorp@tuta[.]com, shinygroup@tuta[.]com, shinycorp@tutanota[.]com, and shinygroup@onionmail[.]com. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.