Kelley, M., Vaya, C. (2024, August 23). Bling Libra’s Tactical Evolution: The Threat Actor Group Behind ShinyHunters Ransomware. Retrieved May 18, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.009 Cloud API |
GroupShinyHunters | ShinyHunters has used the AWS Command Line Interface (CLI) for operations to include a variety of API calls, such as `ListBuckets`, `CreateBucket` and `DeleteBucket`. |
| T1069.003 Cloud Groups |
GroupShinyHunters | ShinyHunters has executed API calls to enumerate permissions for compromised AWS accounts. |
| T1078.004 Cloud Accounts |
GroupShinyHunters | ShinyHunters has used valid cloud accounts to gain initial access or to escalate privileges within cloud environments. Additionally, ShinyHunters has also used valid credentials from public repositories to include access keys to gain access to the victim organization’s AWS environment. |
| T1485 Data Destruction |
GroupShinyHunters | ShinyHunters has executed the `DeleteBucket` API call to delete buckets. |
| T1580 Cloud Infrastructure Discovery |
GroupShinyHunters | ShinyHunters has used Amazon Simple Storage Service (S3) Browser and WinSCP to collect information on S3 bucket configurations. |
| T1585.002 Email Accounts |
GroupShinyHunters | ShinyHunters has established multiple email accounts, such as shinycorp@tutonota[.]com, for use in extortion activities. |
| T1588.002 Tool |
GroupShinyHunters | ShinyHunters has obtained MeshCentral to deploy agents masquerading as legitimate cloud endpoints. ShinyHunters has obtained WinSCP to gather information on S3 bucket configurations. ShinyHunters has obtained ConnectWise and other RMM tools to gain initial access. |
| T1589.001 Credentials |
GroupShinyHunters | ShinyHunters has collected credentials containing PII, ultimately selling the information on their DLS. |
| T1619 Cloud Storage Object Discovery |
GroupShinyHunters | ShinyHunters has used Amazon Simple Storage Service (S3) Browser and WinSCP to access S3 objects. |
| T1657 Financial Theft |
GroupShinyHunters | ShinyHunters has called or sent text messages or emails to employees of victim organizations to demand payment in Bitcoin within 72 hours. Email addresses used in extortion activities include shinycorp@tuta[.]com, shinygroup@tuta[.]com, shinycorp@tutanota[.]com, and shinygroup@onionmail[.]com. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.