ATT&CKReferencesUnit42KelleyVaya_BlingLibra_Aug2024

Unit42KelleyVaya_BlingLibra_Aug2024

Kelley, M., Vaya, C. (2024, August 23). Bling Libra’s Tactical Evolution: The Threat Actor Group Behind ShinyHunters Ransomware. Retrieved May 18, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1059.009
Cloud API
GroupShinyHunters

ShinyHunters has used the AWS Command Line Interface (CLI) for operations to include a variety of API calls, such as `ListBuckets`, `CreateBucket` and `DeleteBucket`.

T1069.003
Cloud Groups
GroupShinyHunters

ShinyHunters has executed API calls to enumerate permissions for compromised AWS accounts.

T1078.004
Cloud Accounts
GroupShinyHunters

ShinyHunters has used valid cloud accounts to gain initial access or to escalate privileges within cloud environments. Additionally, ShinyHunters has also used valid credentials from public repositories to include access keys to gain access to the victim organization’s AWS environment.

T1485
Data Destruction
GroupShinyHunters

ShinyHunters has executed the `DeleteBucket` API call to delete buckets.

T1580
Cloud Infrastructure Discovery
GroupShinyHunters

ShinyHunters has used Amazon Simple Storage Service (S3) Browser and WinSCP to collect information on S3 bucket configurations.

T1585.002
Email Accounts
GroupShinyHunters

ShinyHunters has established multiple email accounts, such as shinycorp@tutonota[.]com, for use in extortion activities.

T1588.002
Tool
GroupShinyHunters

ShinyHunters has obtained MeshCentral to deploy agents masquerading as legitimate cloud endpoints. ShinyHunters has obtained WinSCP to gather information on S3 bucket configurations. ShinyHunters has obtained ConnectWise and other RMM tools to gain initial access.

T1589.001
Credentials
GroupShinyHunters

ShinyHunters has collected credentials containing PII, ultimately selling the information on their DLS.

T1619
Cloud Storage Object Discovery
GroupShinyHunters

ShinyHunters has used Amazon Simple Storage Service (S3) Browser and WinSCP to access S3 objects.

T1657
Financial Theft
GroupShinyHunters

ShinyHunters has called or sent text messages or emails to employees of victim organizations to demand payment in Bitcoin within 72 hours. Email addresses used in extortion activities include shinycorp@tuta[.]com, shinygroup@tuta[.]com, shinycorp@tutanota[.]com, and shinygroup@onionmail[.]com.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.