ShinyHunters
UNC6240Bling Libra
ShinyHunters is a cybercriminal group of unknown origin that is motivated by financial gain. The group is known for its sophisticated attacks against a wide range of targets, including businesses, organizations, and government agencies. ShinyHunters typically uses phishing attacks and exploit kits to gain access to victim networks, where they deploy malware to steal sensitive data, such as… Fuente: MISP
Actividad en Jábega · 12 semanas
10 noticias · vista por primera vez el 21 sept 2026 · la última, el 29 sept 2026
Noticias
- FBI tells ShinyHunters members to turn themselves in after recent arrestBleepingComputer · 29 sept 2026
- Dutch Police Arrest Convicted Hacker in ShinyHunters InvestigationSecurityWeek · 29 sept 2026
- Dutch police confirm arrest in ShinyHunters hacking investigationBleepingComputer · 28 sept 2026
- ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warnsThe Record · 28 sept 2026
- Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters InvestigationKrebsOnSecurity · 28 sept 2026
- Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft CampaignSecurityWeek · 28 sept 2026
- ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacksBleepingComputer · 26 sept 2026
- ShinyHunters hacked Clop leak site using Grav CMS path traversal flawBleepingComputer · 25 sept 2026
- What We Missed: Google Gemini Joins the AI Escape PartyDark Reading · 25 sept 2026
- ShinyHunters Hacked Cl0p. Now What About Cl0p's Victims?Dark Reading · 21 sept 2026
Aparece junto a
Técnicas MITRE ATT&CK
Reconocimiento
T1589.001CredentialsT1593.003Code Repositories 2 reglas SigmaT1595.002Vulnerability Scanning 1 reglas SigmaT1598Phishing for InformationT1598.003Spearphishing Link
Preparación de recursos
T1583.001DomainsT1583.004ServerT1585.002Email AccountsT1587.004ExploitsT1588.002Tool 7 reglas SigmaT1588.007Artificial Intelligence
Acceso inicial
T1078Valid Accounts 82 reglas SigmaT1078.002Domain Accounts 3 reglas SigmaT1078.004Cloud Accounts 35 reglas SigmaT1190Exploit Public-Facing Application 40 reglas SigmaT1195.001Compromise Software Dependencies and Development Tools 2 reglas Sigma
Ejecución
T1059.007JavaScript 26 reglas SigmaT1059.009Cloud API 3 reglas SigmaT1072Software Deployment Tools 4 reglas SigmaT1203Exploitation for Client Execution 31 reglas Sigma
Acceso a credenciales
T1110Brute Force 21 reglas SigmaT1528Steal Application Access Token 13 reglas SigmaT1552.001Credentials In Files 20 reglas Sigma
Descubrimiento
T1016System Network Configuration Discovery 4 reglas SigmaT1018Remote System Discovery 9 reglas SigmaT1069.003Cloud GroupsT1082System Information Discovery 18 reglas SigmaT1083File and Directory Discovery 17 reglas SigmaT1580Cloud Infrastructure DiscoveryT1619Cloud Storage Object Discovery
Movimiento lateral
T1210Exploitation of Remote Services 14 reglas SigmaT1550.001Application Access Token 2 reglas Sigma
Recopilación
T1213.003Code Repositories 4 reglas SigmaT1213.006DatabasesT1530Data from Cloud StorageT1560.002Archive via Library
Mando y control
T1090.003Multi-hop Proxy 3 reglas SigmaT1105Ingress Tool Transfer 40 reglas SigmaT1219Remote Access Tools 46 reglas SigmaT1573.002Asymmetric Cryptography
Exfiltración
Impacto
T1485Data Destruction 15 reglas SigmaT1491.001Internal Defacement 3 reglas SigmaT1657Financial Theft
Stealth
Relaciones por coaparición en noticias, no atribución. Fuentes: MISP galaxy, MITRE ATT&CK y SigmaHQ. attack.mitre.org ↗