ShinyHunters is a financially motivated cybercriminal threat actor best known for large-scale data theft, extortion, and intrusion activity targeting cloud and SaaS environments. The group is widely associated with theft-and-extortion operations in which stolen data is used for "pay or leak" coercion, and has also been linked to ransomware-style victim shaming and public leak activity. ShinyHunters is not a nation-state actor; it is generally tracked as part of the cybercrime ecosystem. Known aliases and related tracking names include ShinyHunter, shinyhunters, shiny_hunters, Bling Libra, UNC6040, and UNC6240. Some reporting distinguishes between clusters associated with initial access and follow-on extortion while noting that the operators or affiliates have claimed the ShinyHunters name during victim interactions. Related activity has also overlapped with other tracked clusters in the broader ecosystem. Recent operations have been strongly associated with attacks against Salesforce and other SaaS-connected business applications. Tradecraft includes voice phishing in which operators impersonate IT support personnel to trick users into authorizing malicious OAuth connected applications, often masquerading as legitimate enterprise tools. Once consent is granted, the attackers inherit the victim user's existing privileges, enabling persistent API-based access, CRM data discovery, and bulk exfiltration while blending into normal application traffic. This activity has been notable because it abuses trusted identity and application relationships rather than relying on malware deployment or exploitation of an inherent Salesforce software vulnerability. ShinyHunters-linked activity has also involved compromise of third-party vendors and downstream SaaS integrations. In these cases, attackers obtained OAuth tokens, refresh tokens, or other connection secrets from trusted service providers and then used those trusted integrations to access customer Salesforce environments and extract data. Additional observed tradecraft includes abuse of misconfigured guest access in Salesforce Experience Cloud and Aura endpoints, including chained GraphQL-style requests to retrieve excessive data where guest permissions were overly permissive. The group has targeted organizations across multiple sectors, including retail, education, manufacturing, healthcare, telecommunications, travel, and technology. Victim reporting and public investigations have tied the name to campaigns affecting enterprises, universities, telecom providers, and cloud-connected service platforms. Education and CRM-heavy environments have been especially prominent in recent reporting, with operations focused on high-volume theft of customer, student, employee, and support-case data. Operationally, ShinyHunters is associated with social engineering, credential theft, abuse of legitimate cloud application integrations, persistence through approved applications, large-scale data collection from information repositories, and exfiltration over web services. Publicly described ATT&CK-aligned behaviors include Voice Phishing, Steal Application Access Token, Cloud Application Integration abuse, Data from Information Repositories including CRM platforms, and Exfiltration Over Web Service. The group's methods are designed to evade traditional authentication-focused detections by operating through approved apps, valid sessions, and trusted integrations. ShinyHunters has also been associated with public extortion branding in which victims are pressured with deadlines and threats of data publication if payment is not made. In some incidents, the actor or affiliates have claimed destructive or ransomware-related impact, but the most consistently corroborated pattern is data theft followed by extortion rather than classic encryption-led ransomware operations. Overall, ShinyHunters is a prominent cybercriminal brand associated with opportunistic but high-impact intrusions, especially where identity workflows, OAuth trust relationships, third-party SaaS integrations, and weak cloud configuration controls can be abused to obtain and monetize sensitive data at scale.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
28 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
The attack relied on a zero-day flaw, CVE-2026-35273, which was patched later, with the vulnerability already being actively exploited.
Oracle E-Business Suite was the target of a large scale Cl0p ransomware campaign just months ago via CVE-2025-61882... A critical zero day in Oracle EBS Concurrent Processing, exploited by the Cl0p ransomware gang...
BleepingComputer reported that threat actors leveraged credentials stolen through the Trivy supply chain compromise (CVE-2026-33634) to breach Cisco's internal development environment... The CISA KEV remediation deadline for CVE-2026-33634 is today, April 8, 2026... Beyond patching Trivy to v0.69.2+, trivy-action to v0.35.0, or setup-trivy to v0.2.6, organizations must also complete credential rotation.
CISA on Monday added CVE-2025-61884 to its Known Exploited Vulnerabilities (KEV) catalog, confirming its exploitation.
According to data obtained from a public Telegram channel operated by the ShinyHunters team, the threat actor persona ‘Yukari’ exploited an Oracle Access Manager vulnerability (CVE-2021-35587). The attack targeted financial institutions and manufacturers.
71 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting data theft and persistent access operations against Salesforce environments by abusing trusted OAuth app approvals, voice phishing employees, leveraging compromised SaaS integrations, and exploiting overly broad guest access to query and exfiltrate CRM data.
Cluster used for the initial access phase of the Salesforce-focused campaign, particularly the vishing-led OAuth consent abuse.
Targeted Microsoft Entra SSO accounts in SaaS data-theft attacks using stolen credentials.
Conducting a pay-or-leak extortion campaign against Glendale Community College and publishing stolen data online after presumed non-payment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.