ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1057×

46 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
GroupShinyHunters

ShinyHunters has collected machine names and IP addresses by parsing the process scheduler configuration file psappsrv.cfg.

T1018
Remote System Discovery
GroupShinyHunters

ShinyHunters has enumerated the internal subnet using ` cat /etc/hosts | grep -E "[redacted_victim_string]"`.

T1036.005
Match Legitimate Resource Name or Location
GroupShinyHunters

ShinyHunters has disguised MeshCentral agent binaries as Microsoft Azure services, e.g. meshagent32-azure-ops.exe, meshagent64-azure-ops.exe, and meshagent64-v2.exe.

T1059.007
JavaScript
GroupShinyHunters

ShinyHunters has used the MeshCentral command-line interface utility meshctrl.js and npm to interact with compromised systems. Specifically for npm, ShinyHunters has checked for the authenticode tool using the command `npm list global authenticode`. Additionally, ShinyHunters has used the MeshCentral command to execute the propagation script: ` node meshctrl.js RunCommand --loginuser admin --loginpass '[password]' --id '[agent_id]' --run 'bash /tmp/[victim_abbreviation]_fanout.sh' `.

T1059.009
Cloud API
GroupShinyHunters

ShinyHunters has used the AWS Command Line Interface (CLI) for operations to include a variety of API calls, such as `ListBuckets`, `CreateBucket` and `DeleteBucket`.

T1069.003
Cloud Groups
GroupShinyHunters

ShinyHunters has executed API calls to enumerate permissions for compromised AWS accounts.

T1072
Software Deployment Tools
GroupShinyHunters

ShinyHunters has abused software deployment tools for lateral movement.

T1078
Valid Accounts
GroupShinyHunters

ShinyHunters has used valid high-privileged SSO users as leverage during negotiations.

T1078.002
Domain Accounts
GroupShinyHunters

ShinyHunters has used valid domain accounts to gain initial access or to escalate privileges within environments.

T1078.004
Cloud Accounts
GroupShinyHunters

ShinyHunters has used valid cloud accounts to gain initial access or to escalate privileges within cloud environments. Additionally, ShinyHunters has also used valid credentials from public repositories to include access keys to gain access to the victim organization’s AWS environment.

T1082
System Information Discovery
GroupShinyHunters

ShinyHunters has used the MeshCentral command-line utility meshctrl.js to collect hostnames and IDs of compromised systems.

T1083
File and Directory Discovery
GroupShinyHunters

ShinyHunters has checked mount points for Oracle PeopleSoft configurations and has checked the process scheduler configuration file psappsrv.cfg. Additionally, ShinyHunters has read WebLogic server XML configurations files (config.xml).

T1090.003
Multi-hop Proxy
GroupShinyHunters

ShinyHunters has used Tor to host their DLS.

T1105
Ingress Tool Transfer
GroupShinyHunters

ShinyHunters has deployed custom scripts to targeted systems from customized MeshAgents in their staging environment.

T1110
Brute Force
GroupShinyHunters

ShinyHunters has performed brute force attacks against edge devices, such as VPNs or firewall solutions.

T1190
Exploit Public-Facing Application
GroupShinyHunters

ShinyHunters has exploited CVE-2026-35273 against Oracle PeopleSoft application infrastructure. ShinyHunters has exploited known vulnerabilities in internet-facing servers.

T1195.001
Compromise Software Dependencies and Development Tools
GroupShinyHunters

ShinyHunters has compromised CI/CD pipelines by gaining access to high privilege engineering accounts on Git version control, BrowserStack, JFrog and other cloud project management platforms.

T1203
Exploitation for Client Execution
GroupShinyHunters

ShinyHunters has exploited vulnerabilities in the target company’s GitHub repository source code to enable more complex follow-on third-party or supply chain attacks.

T1210
Exploitation of Remote Services
GroupShinyHunters

ShinyHunters has exploited vulnerabilities in remote services for lateral movement.

T1213.003
Code Repositories
GroupShinyHunters

ShinyHunters has gathered information from and has searched for vulnerabilities in the target company’s GitHub repository source code.

T1213.006
Databases
GroupShinyHunters

ShinyHunters has collected Salesforce datasets from victims in the airline and retail sectors.

T1219
Remote Access Tools
GroupShinyHunters

ShinyHunters has used MeshCentral and ConnectWise to gain initial access, to run administrative command queries and to deploy the custom lateral movement and defacement script [victim_abbreviation]_fanout.sh.

T1485
Data Destruction
GroupShinyHunters

ShinyHunters has executed the `DeleteBucket` API call to delete buckets.

T1491.001
Internal Defacement
GroupShinyHunters

ShinyHunters has left ransom notes titled README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT.

T1528
Steal Application Access Token
GroupShinyHunters

ShinyHunters has stolen valid OAuth credentials from DevOps personnel or a company GitHub repository. Additionally, ShinyHunters has stolen application access tokens to access cloud services and to bypass authentication mechanisms.

T1530
Data from Cloud Storage
GroupShinyHunters

ShinyHunters has collected data from insecure cloud buckets.

T1550.001
Application Access Token
GroupShinyHunters

ShinyHunters has used stolen OAuth keys to access cloud infrastructure and to bypass two-factor authentication.

T1552.001
Credentials In Files
GroupShinyHunters

ShinyHunters has gathered PII from database infrastructure.

T1560.002
Archive via Library
GroupShinyHunters

ShinyHunters has used the following command to compress collected data: ` pv -s "$(du -sb exfil | awk '{print $1}')" | zstd -3 -T0 -o exfil.tar.zst `.

T1567
Exfiltration Over Web Service
GroupShinyHunters

ShinyHunters has used compromised Salesforce CRM (Customer Relationship Management) dashboards to exfiltrate bulk data. Additionally, ShinyHunters has used LimeWire, a file-sharing service, to showcase samples of stolen data.

T1573.002
Asymmetric Cryptography
GroupShinyHunters

ShinyHunters has established a connection between the staging host and the C2 using SSH.

T1580
Cloud Infrastructure Discovery
GroupShinyHunters

ShinyHunters has used Amazon Simple Storage Service (S3) Browser and WinSCP to collect information on S3 bucket configurations.

T1583.001
Domains
GroupShinyHunters

ShinyHunters has established clearnet and Tor data leak sites (DLS) including one named “SHINYHUNTERS” for the exfiltration and posting of stolen data. Additionally, ShinyHunters has registered domains that mimic legitimate Microsoft Azure NetApp Files endpoints, such as azurenetfiles[.]net, and legitimate Okta SSO login pages, such as trial-6857053.okta[.]com.

T1583.004
Server
GroupShinyHunters

ShinyHunters has used five IP addresses to host Python SimpleHTTP servers on port 8888, which exposed staging materials, customized agents, and .bash_history files.

T1585.002
Email Accounts
GroupShinyHunters

ShinyHunters has established multiple email accounts, such as shinycorp@tutonota[.]com, for use in extortion activities.

T1587.004
Exploits
GroupShinyHunters

ShinyHunters has exploited zero-day vulnerability CVE-2026-35273 against Oracle PeopleSoft application infrastructure.

T1588.002
Tool
GroupShinyHunters

ShinyHunters has obtained MeshCentral to deploy agents masquerading as legitimate cloud endpoints. ShinyHunters has obtained WinSCP to gather information on S3 bucket configurations. ShinyHunters has obtained ConnectWise and other RMM tools to gain initial access.

T1588.007
Artificial Intelligence
GroupShinyHunters

ShinyHunters has used Bland AI to create conversational pathways tailored to specific scenarios during voice phishing attacks.

T1589.001
Credentials
GroupShinyHunters

ShinyHunters has collected credentials containing PII, ultimately selling the information on their DLS.

T1593.003
Code Repositories
GroupShinyHunters

ShinyHunters has searched through target companies’ GitHub repositories for login credentials or API keys.

T1595.002
Vulnerability Scanning
GroupShinyHunters

ShinyHunters has searched through victim companies’ GitHub repositories for vulnerabilities.

T1598
Phishing for Information
GroupShinyHunters

ShinyHunters has sent phishing emails to Microsoft Office 365 corporate users in order to steal credentials.

T1598.003
Spearphishing Link
GroupShinyHunters

ShinyHunters has used spearphishing emails with malicious links to gain initial access and credentials.

T1619
Cloud Storage Object Discovery
GroupShinyHunters

ShinyHunters has used Amazon Simple Storage Service (S3) Browser and WinSCP to access S3 objects.

T1657
Financial Theft
GroupShinyHunters

ShinyHunters has called or sent text messages or emails to employees of victim organizations to demand payment in Bitcoin within 72 hours. Email addresses used in extortion activities include shinycorp@tuta[.]com, shinygroup@tuta[.]com, shinycorp@tutanota[.]com, and shinygroup@onionmail[.]com.

T1684
Social Engineering
GroupShinyHunters

ShinyHunters has used social engineering to demand payment from victims.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.