Skip to main content
Mallory
Back to malware
MalwareRansomwareUsed by 2 actors

ShinyHunters

ShinyHunters is a data-extortion threat group associated in some reporting with “ShinyHunters ransomware,” although the provided content repeatedly states it operates as a pure data-extortion actor and has never encrypted victim files. Its activity centers on large-scale data theft, leak-based extortion, and exposure or sale of stolen datasets, with a reported shift in 2024 toward directly extorting victims rather than primarily selling or publishing stolen data. Reported targeting includes healthcare-adjacent organizations such as medical technology companies, broader enterprise victims, and centralized data environments including Salesforce and cloud storage platforms. The group has been described as using social engineering against Business Process Outsourcing personnel while posing as IT support to obtain legitimate access to Salesforce environments, and as exploiting exposed credentials, weak configurations, or vulnerabilities in widely used services. In one Unit 42 incident involving the Bling Libra group behind ShinyHunters, attackers used exposed AWS IAM credentials with AmazonS3FullAccess to enumerate S3 buckets via AWS CLI, S3 Browser, and WinSCP, then deleted buckets and attempted to create new buckets named with variants of an extortion contact address. The content notes that ShinyHunters activity has been linked to mass data exfiltration, delayed extortion demands months after intrusion, and public leak pressure when victims refuse payment. Mentioned incidents and claims in the content include a Medtronic breach involving unauthorized access to corporate systems and potential large-scale data exfiltration, a breach claimed against Odido involving data on 6.2 million customers that was reportedly published after non-payment, and a claimed Wynn Resorts case. Reported indicators and artifacts include S3 Browser and WinSCP user-agent strings in CloudTrail, bucket names containing variants of “contact-shinycorp-tutanota-com-#”, and the extortion contact email “shinycorp@tutonota[.]com” as listed in the source content.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
ShinyHunters

ShinyHunters operates in a few different avenues (sometimes direct extortion, sometimes extortion-as-a-service with other actors)... These attacks leverage social engineering tactics against the target organization’s Business Process Outsourcing (BPO) personnel with a specific focus on accessing Salesforce environments.

via coveware blogcoveware.com
Scattered Lapsus$ Hunters

"ShinyHunters has operated this model exclusively. They have never encrypted a single victim’s file."

via osint team blogosintteam.blog
ACTIVITY FEED

Recent activity

5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.