ATT&CKReferencesSOCRadar_ShinyHunters_Mar2024

SOCRadar_ShinyHunters_Mar2024

SOCRadar. (2024, March 18). Dark Web Profile: ShinyHunters. Retrieved May 18, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1072
Software Deployment Tools
GroupShinyHunters

ShinyHunters has abused software deployment tools for lateral movement.

T1078.002
Domain Accounts
GroupShinyHunters

ShinyHunters has used valid domain accounts to gain initial access or to escalate privileges within environments.

T1078.004
Cloud Accounts
GroupShinyHunters

ShinyHunters has used valid cloud accounts to gain initial access or to escalate privileges within cloud environments. Additionally, ShinyHunters has also used valid credentials from public repositories to include access keys to gain access to the victim organization’s AWS environment.

T1210
Exploitation of Remote Services
GroupShinyHunters

ShinyHunters has exploited vulnerabilities in remote services for lateral movement.

T1528
Steal Application Access Token
GroupShinyHunters

ShinyHunters has stolen valid OAuth credentials from DevOps personnel or a company GitHub repository. Additionally, ShinyHunters has stolen application access tokens to access cloud services and to bypass authentication mechanisms.

T1530
Data from Cloud Storage
GroupShinyHunters

ShinyHunters has collected data from insecure cloud buckets.

T1580
Cloud Infrastructure Discovery
GroupShinyHunters

ShinyHunters has used Amazon Simple Storage Service (S3) Browser and WinSCP to collect information on S3 bucket configurations.

T1593.003
Code Repositories
GroupShinyHunters

ShinyHunters has searched through target companies’ GitHub repositories for login credentials or API keys.

T1595.002
Vulnerability Scanning
GroupShinyHunters

ShinyHunters has searched through victim companies’ GitHub repositories for vulnerabilities.

T1598.003
Spearphishing Link
GroupShinyHunters

ShinyHunters has used spearphishing emails with malicious links to gain initial access and credentials.

T1657
Financial Theft
GroupShinyHunters

ShinyHunters has called or sent text messages or emails to employees of victim organizations to demand payment in Bitcoin within 72 hours. Email addresses used in extortion activities include shinycorp@tuta[.]com, shinygroup@tuta[.]com, shinycorp@tutanota[.]com, and shinygroup@onionmail[.]com.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.