Shinycorp
ShinyCorp is described in the provided content as a cybercriminal actor associated with ShinyHunters and with the ShinySpider (also written Sh1nySp1d3r or ShinySP1D3R) ransomware-as-a-service operation. The content states that ShinyCorp actively sold stolen datasets together with ransomware partners and other e-crime actors, with prices exceeding $1 million per company. It also describes ShinyHunters/ShinyCorp as responsible for attacks and says the group sold stolen data while working with extortion partners. The associated activity in the content includes data theft and extortion, including theft of large customer datasets from airline victims, seven-figure extortion demands, and publication of stolen data samples on LimeWire to pressure victims. The broader operation linked in the content is described as targeting VMware ESXi environments for large-scale encryption of virtual machines, using ChaCha20 with RSA-2048-protected keys, appending unique extensions, and dropping ransom notes such as R3ADME_xxxxxxxx.txt. The content further claims expansion in 2025 to AI-enabled voice phishing, supply-chain compromise, and insider recruitment, and alleges collaboration with affiliates of Scattered Spider and The Com against single sign-on platforms in the retail, airline, and telecommunications sectors. No nation-state attribution is stated in the provided content. Known associated names and aliases directly mentioned are ShinyHunters and ShinySpider/Sh1nySp1d3r/ShinySP1D3R.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Consumer Discretionary Distribution & Retail
- Transportation
- Telecommunication Services
Tradecraft
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Recent activity
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.