Real-world descriptions of how a group, tool or campaign used a technique.
46 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
GroupShinyHunters | ShinyHunters has collected machine names and IP addresses by parsing the process scheduler configuration file psappsrv.cfg. |
| T1018 Remote System Discovery |
GroupShinyHunters | ShinyHunters has enumerated the internal subnet using ` cat /etc/hosts | grep -E "[redacted_victim_string]"`. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupShinyHunters | ShinyHunters has disguised MeshCentral agent binaries as Microsoft Azure services, e.g. meshagent32-azure-ops.exe, meshagent64-azure-ops.exe, and meshagent64-v2.exe. |
| T1059.007 JavaScript |
GroupShinyHunters | ShinyHunters has used the MeshCentral command-line interface utility meshctrl.js and npm to interact with compromised systems. Specifically for npm, ShinyHunters has checked for the authenticode tool using the command `npm list global authenticode`. Additionally, ShinyHunters has used the MeshCentral command to execute the propagation script: ` node meshctrl.js RunCommand --loginuser admin --loginpass '[password]' --id '[agent_id]' --run 'bash /tmp/[victim_abbreviation]_fanout.sh' `. |
| T1059.009 Cloud API |
GroupShinyHunters | ShinyHunters has used the AWS Command Line Interface (CLI) for operations to include a variety of API calls, such as `ListBuckets`, `CreateBucket` and `DeleteBucket`. |
| T1069.003 Cloud Groups |
GroupShinyHunters | ShinyHunters has executed API calls to enumerate permissions for compromised AWS accounts. |
| T1072 Software Deployment Tools |
GroupShinyHunters | ShinyHunters has abused software deployment tools for lateral movement. |
| T1078 Valid Accounts |
GroupShinyHunters | ShinyHunters has used valid high-privileged SSO users as leverage during negotiations. |
| T1078.002 Domain Accounts |
GroupShinyHunters | ShinyHunters has used valid domain accounts to gain initial access or to escalate privileges within environments. |
| T1078.004 Cloud Accounts |
GroupShinyHunters | ShinyHunters has used valid cloud accounts to gain initial access or to escalate privileges within cloud environments. Additionally, ShinyHunters has also used valid credentials from public repositories to include access keys to gain access to the victim organization’s AWS environment. |
| T1082 System Information Discovery |
GroupShinyHunters | ShinyHunters has used the MeshCentral command-line utility meshctrl.js to collect hostnames and IDs of compromised systems. |
| T1083 File and Directory Discovery |
GroupShinyHunters | ShinyHunters has checked mount points for Oracle PeopleSoft configurations and has checked the process scheduler configuration file psappsrv.cfg. Additionally, ShinyHunters has read WebLogic server XML configurations files (config.xml). |
| T1090.003 Multi-hop Proxy |
GroupShinyHunters | ShinyHunters has used Tor to host their DLS. |
| T1105 Ingress Tool Transfer |
GroupShinyHunters | ShinyHunters has deployed custom scripts to targeted systems from customized MeshAgents in their staging environment. |
| T1110 Brute Force |
GroupShinyHunters | ShinyHunters has performed brute force attacks against edge devices, such as VPNs or firewall solutions. |
| T1190 Exploit Public-Facing Application |
GroupShinyHunters | ShinyHunters has exploited CVE-2026-35273 against Oracle PeopleSoft application infrastructure. ShinyHunters has exploited known vulnerabilities in internet-facing servers. |
| T1195.001 Compromise Software Dependencies and Development Tools |
GroupShinyHunters | ShinyHunters has compromised CI/CD pipelines by gaining access to high privilege engineering accounts on Git version control, BrowserStack, JFrog and other cloud project management platforms. |
| T1203 Exploitation for Client Execution |
GroupShinyHunters | ShinyHunters has exploited vulnerabilities in the target company’s GitHub repository source code to enable more complex follow-on third-party or supply chain attacks. |
| T1210 Exploitation of Remote Services |
GroupShinyHunters | ShinyHunters has exploited vulnerabilities in remote services for lateral movement. |
| T1213.003 Code Repositories |
GroupShinyHunters | ShinyHunters has gathered information from and has searched for vulnerabilities in the target company’s GitHub repository source code. |
| T1213.006 Databases |
GroupShinyHunters | ShinyHunters has collected Salesforce datasets from victims in the airline and retail sectors. |
| T1219 Remote Access Tools |
GroupShinyHunters | ShinyHunters has used MeshCentral and ConnectWise to gain initial access, to run administrative command queries and to deploy the custom lateral movement and defacement script [victim_abbreviation]_fanout.sh. |
| T1485 Data Destruction |
GroupShinyHunters | ShinyHunters has executed the `DeleteBucket` API call to delete buckets. |
| T1491.001 Internal Defacement |
GroupShinyHunters | ShinyHunters has left ransom notes titled README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT. |
| T1528 Steal Application Access Token |
GroupShinyHunters | ShinyHunters has stolen valid OAuth credentials from DevOps personnel or a company GitHub repository. Additionally, ShinyHunters has stolen application access tokens to access cloud services and to bypass authentication mechanisms. |
| T1530 Data from Cloud Storage |
GroupShinyHunters | ShinyHunters has collected data from insecure cloud buckets. |
| T1550.001 Application Access Token |
GroupShinyHunters | ShinyHunters has used stolen OAuth keys to access cloud infrastructure and to bypass two-factor authentication. |
| T1552.001 Credentials In Files |
GroupShinyHunters | ShinyHunters has gathered PII from database infrastructure. |
| T1560.002 Archive via Library |
GroupShinyHunters | ShinyHunters has used the following command to compress collected data: ` pv -s "$(du -sb exfil | awk '{print $1}')" | zstd -3 -T0 -o exfil.tar.zst `. |
| T1567 Exfiltration Over Web Service |
GroupShinyHunters | ShinyHunters has used compromised Salesforce CRM (Customer Relationship Management) dashboards to exfiltrate bulk data. Additionally, ShinyHunters has used LimeWire, a file-sharing service, to showcase samples of stolen data. |
| T1573.002 Asymmetric Cryptography |
GroupShinyHunters | ShinyHunters has established a connection between the staging host and the C2 using SSH. |
| T1580 Cloud Infrastructure Discovery |
GroupShinyHunters | ShinyHunters has used Amazon Simple Storage Service (S3) Browser and WinSCP to collect information on S3 bucket configurations. |
| T1583.001 Domains |
GroupShinyHunters | ShinyHunters has established clearnet and Tor data leak sites (DLS) including one named “SHINYHUNTERS” for the exfiltration and posting of stolen data. Additionally, ShinyHunters has registered domains that mimic legitimate Microsoft Azure NetApp Files endpoints, such as azurenetfiles[.]net, and legitimate Okta SSO login pages, such as trial-6857053.okta[.]com. |
| T1583.004 Server |
GroupShinyHunters | ShinyHunters has used five IP addresses to host Python SimpleHTTP servers on port 8888, which exposed staging materials, customized agents, and .bash_history files. |
| T1585.002 Email Accounts |
GroupShinyHunters | ShinyHunters has established multiple email accounts, such as shinycorp@tutonota[.]com, for use in extortion activities. |
| T1587.004 Exploits |
GroupShinyHunters | ShinyHunters has exploited zero-day vulnerability CVE-2026-35273 against Oracle PeopleSoft application infrastructure. |
| T1588.002 Tool |
GroupShinyHunters | ShinyHunters has obtained MeshCentral to deploy agents masquerading as legitimate cloud endpoints. ShinyHunters has obtained WinSCP to gather information on S3 bucket configurations. ShinyHunters has obtained ConnectWise and other RMM tools to gain initial access. |
| T1588.007 Artificial Intelligence |
GroupShinyHunters | ShinyHunters has used Bland AI to create conversational pathways tailored to specific scenarios during voice phishing attacks. |
| T1589.001 Credentials |
GroupShinyHunters | ShinyHunters has collected credentials containing PII, ultimately selling the information on their DLS. |
| T1593.003 Code Repositories |
GroupShinyHunters | ShinyHunters has searched through target companies’ GitHub repositories for login credentials or API keys. |
| T1595.002 Vulnerability Scanning |
GroupShinyHunters | ShinyHunters has searched through victim companies’ GitHub repositories for vulnerabilities. |
| T1598 Phishing for Information |
GroupShinyHunters | ShinyHunters has sent phishing emails to Microsoft Office 365 corporate users in order to steal credentials. |
| T1598.003 Spearphishing Link |
GroupShinyHunters | ShinyHunters has used spearphishing emails with malicious links to gain initial access and credentials. |
| T1619 Cloud Storage Object Discovery |
GroupShinyHunters | ShinyHunters has used Amazon Simple Storage Service (S3) Browser and WinSCP to access S3 objects. |
| T1657 Financial Theft |
GroupShinyHunters | ShinyHunters has called or sent text messages or emails to employees of victim organizations to demand payment in Bitcoin within 72 hours. Email addresses used in extortion activities include shinycorp@tuta[.]com, shinygroup@tuta[.]com, shinycorp@tutanota[.]com, and shinygroup@onionmail[.]com. |
| T1684 Social Engineering |
GroupShinyHunters | ShinyHunters has used social engineering to demand payment from victims. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.