Threat Actor Unknown origin
ShinyHunters
ShinyHunters is a cybercriminal group of unknown origin that is motivated by financial gain. The group is known for its sophisticated attacks against a wide range of targets, including businesses, organizations, and government agencies. ShinyHunters typically uses phishing attacks and exploit kits to gain access to victim networks, where they deploy malware to steal sensitive data, such as names, addresses, phone numbers, Social Security numbers, and credit card information.
Indicators of Compromise 62
Domain 162[.]219[.]30[.]165 Domain FBIjobs[.]gov Domain add-passkey[.]com Domain apply[.]fbijobs[.]gov Domain cargurus[.]com Domain city-forum[.]com Domain david[.]flhsmv[.]gov Domain domainlify[.]net Domain help@trezor[.]io Domain idokta[.]com Domain integratedsso[.]com Domain keysyncos[.]com Domain oktasession[.]com Domain oskeysync[.]com Domain passkey Domain passkeyhelpdesk[.]com Domain policenationale[.]cc Domain portalsetuphub[.]com Domain proton66[.]ooo Domain ringcentral[.]com Domain secure-passkey[.]com Domain service-nowinc[.]com Domain setupmypasskey[.]com Domain setupsso[.]com Domain shinyhunters[.]com Domain syncmykey[.]com Email service[@]ringcentral[.]com Filename Kuailian VPN Filename Kuailian VPN.msi Filename PSEMHUB.war Filename Ple64.exe Filename SECOH-QAD.exe Filename SECOMS64 Filename VID001.exe Filename al-Najm al-thāqib Filename f_000cd7.html Filename node.exe Filename small text file Filename tunnel.jsp Filename tunnel.jspx Filename u.jsp Filename u2.jsp Filename u992574.dll Filename x.jsp GitHub User GRUB1 GitHub User ShadowByt3$ GitHub User frkoo GitHub User pepegit666 MD5 2915b3f8b703eb744fc54c81f4a9c67f MD5 38de5b216c33833af710e88f7f64fc98 MD5 bf9672ec85283fdf002d83662f0b08b7 MD5 dbd8dbecaa80795c135137d69921fdba SHA-256 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f SHA-256 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 SHA-256 c0ad494457dcd9e964378760fb6aca86a23622045bca851d8f3ab49ec33978fe SHA-256 e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba IP 158[.]220[.]87[.]79 IP 162[.]219[.]30[.]165 IP 179[.]43[.]185[.]230 IP 91[.]211[.]244[.]119 Package Braintree.Net Package Jscrambler
MITRE ATT&CK TTPs 90
T1003 T1003.002 T1020 T1021 T1021.001 T1021.002 T1021.003 T1021.004 T1040 T1046 T1055 T1056.001 T1056.002 T1059 T1059.001 T1059.003 T1071 T1071.001 T1071.004 T1078 T1078.002 T1078.004 T1082 T1083 T1085 T1087 T1087.003 T1090 T1090.002 T1095 T1098 T1102 T1105 T1110 T1110.001 T1113 T1114 T1120 T1132 T1133 T1135 T1190 T1192 T1195 T1195.001 T1195.002 T1202 T1204.002 T1210 T1212 T1213 T1400 T1480 T1482 T1484.001 T1485 T1486 T1489 T1490 T1491 T1495 T1496 T1499 T1529 T1530 T1531 T1538 T1538.001 T1542 T1543.003 T1557 T1558 T1558.003 T1566 T1566.001 T1566.002 T1567 T1567.001 T1567.002 T1568 T1568.002 T1570 T1573 T1588 T1588.001 T1588.002 T1595 T1595.002 T1611 T1659
OS Credential Dumping
Credential Access
Security Account Manager
Credential Access
Automated Exfiltration
Exfiltration
Remote Services
Lateral Movement
Remote Desktop Protocol
Lateral Movement
SMB/Windows Admin Shares
Lateral Movement
Distributed Component Object Model
Lateral Movement
SSH
Lateral Movement
Network Sniffing
Credential Access
Network Service Discovery
Discovery
Process Injection
Defense Evasion
Keylogging
Collection
GUI Input Capture
Collection
Command and Scripting Interpreter
Execution
PowerShell
Execution
Windows Command Shell
Execution
Application Layer Protocol
Command And Control
Web Protocols
Command And Control
DNS
Command And Control
Valid Accounts
Defense Evasion
Domain Accounts
Defense Evasion
Cloud Accounts
Defense Evasion
System Information Discovery
Discovery
File and Directory Discovery
Discovery
T1085
Account Discovery
Discovery
Email Account
Discovery
Proxy
Command And Control
External Proxy
Command And Control
Non-Application Layer Protocol
Command And Control
Account Manipulation
Persistence
Web Service
Command And Control
Ingress Tool Transfer
Command And Control
Brute Force
Credential Access
Password Guessing
Credential Access
Screen Capture
Collection
Email Collection
Collection
Peripheral Device Discovery
Discovery
Data Encoding
Command And Control
External Remote Services
Persistence
Network Share Discovery
Discovery
Exploit Public-Facing Application
Initial Access
T1192
Supply Chain Compromise
Initial Access
Compromise Software Dependencies and Development Tools
Initial Access
Compromise Software Supply Chain
Initial Access
Indirect Command Execution
Defense Evasion
Malicious File
Execution
Exploitation of Remote Services
Lateral Movement
Exploitation for Credential Access
Credential Access
Data from Information Repositories
Collection
T1400
Execution Guardrails
Defense Evasion
Domain Trust Discovery
Discovery
Group Policy Modification
Defense Evasion
Data Destruction
Impact
Data Encrypted for Impact
Impact
Service Stop
Impact
Inhibit System Recovery
Impact
Defacement
Impact
Firmware Corruption
Impact
Resource Hijacking
Impact
Endpoint Denial of Service
Impact
System Shutdown/Reboot
Impact
Data from Cloud Storage
Collection
Account Access Removal
Impact
Cloud Service Dashboard
Discovery
T1538.001
Pre-OS Boot
Defense Evasion
Windows Service
Persistence
Adversary-in-the-Middle
Credential Access
Steal or Forge Kerberos Tickets
Credential Access
Kerberoasting
Credential Access
Phishing
Initial Access
Spearphishing Attachment
Initial Access
Spearphishing Link
Initial Access
Exfiltration Over Web Service
Exfiltration
Exfiltration to Code Repository
Exfiltration
Exfiltration to Cloud Storage
Exfiltration
Dynamic Resolution
Command And Control
Domain Generation Algorithms
Command And Control
Lateral Tool Transfer
Lateral Movement
Encrypted Channel
Command And Control
Obtain Capabilities
Resource Development
Malware
Resource Development
Tool
Resource Development
Active Scanning
Reconnaissance
Vulnerability Scanning
Reconnaissance
Escape to Host
Privilege Escalation
Content Injection
Initial Access
Source Articles
Hackers stole Pentagon personnel records of over 3 million people
Hackers breached the Pentagon's Defense Manpower Data Center (DMDC) human resources management system between October 2025 and July 2026 by exploiting a vulnerability in its file-sharing systems. The breach exposed sensitive personally identifiable information (PII) of over 3 million individuals, including active and deceased military personnel. Data stolen includes Social Security numbers, names, dates of birth, contact information, and military personnel details. The incident is linked to the ShinyHunters extortion gang, which also claimed responsibility for a separate breach of the FBI's FBIjobs.gov site using an Oracle PeopleSoft zero-day vulnerability.
bleeping-computer ·2d ago
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
Threat actor UNC6240, linked to ShinyHunters, is exploiting CVE-2026-35273, a critical unauthenticated remote code execution vulnerability in Oracle PeopleSoft, to deploy web shells and establish persistent access. The attackers bypass web application firewall (WAF) protections by URL-encoding the 'P' character as '%50' in requests to the vulnerable PSEMHUB endpoint. Exploitation leads to fileless command execution, deployment of JSP web shells, and installation of the SIDEEYE backdoor and Neo-reGeorg tunneling toolkit for data exfiltration and lateral movement. Targets span multiple sectors including education, healthcare, government, and technology, with the threat actor demonstrating root- and SYSTEM-level access on compromised systems.
hacker-news ·1w ago
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
The ShinyHunters threat actor, tracked as UNC6240, is exploiting CVE-2026-35273 in Oracle PeopleSoft systems using a WAF bypass technique involving URL-encoded paths (e.g., '/%50SEMHUB/') to evade detection. This allows continued exploitation of unpatched servers where WAF rules were expected to block access. The attackers deploy JSP web shells (x.jsp, u.jsp, u2.jsp, tunnel.jsp, tunnel.jspx), execute in-memory commands, and deploy the SIDEEYE backdoor via 'Ple64.exe' on Windows systems. They also use Neo-reGeorg for tunneling and MeshAgent for persistence on Linux systems, targeting sectors including education, government, healthcare, and technology.
bleeping-computer ·6d ago
ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
The Clop ransomware gang's data leak site was compromised by the ShinyHunters extortion group through an unpatched path traversal vulnerability in Grav CMS version 1.7.43. ShinyHunters exploited the flaw to upload malicious files, deface the site, and claim theft of source code, plugins, server logs, and Tor private keys, subsequently issuing a ransom demand. Grav CMS confirmed the vulnerability, tracked as CVE-2026-42608, resides in the core of Grav and was fixed in Grav 2.0 but not backported to the 1.7 branch until version 1.7.53.4 was released following disclosure.
bleeping-computer ·1w ago
ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
ShinyHunters, a cyber extortion group, claimed responsibility for breaching the U.S. Federal Bureau of Investigation (FBI), asserting they exfiltrated sensitive data on current and former agents and job applicants. The group reportedly exploited a zero-day vulnerability in Oracle PeopleSoft to gain remote code execution and deface the FBI's jobs portal, FBIjobs.gov, with a taunting banner. They linked the attack to retaliation for an FBI public service announcement criticizing their prior activities, particularly around the Canvas LMS breach. While the FBI has acknowledged awareness of the claims and is investigating, no technical evidence or data dumps have been independently verified yet.
hacker-news ·1w ago
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
The ShinyHunters extortion gang claims to have breached FBI systems using an unpatched zero-day vulnerability in Oracle PeopleSoft, enabling remote code execution and lateral movement into FBI-managed AWS GovCloud infrastructure. They allege exfiltration of 2–3TB of sensitive data, including personally identifiable and health-related information of current and former FBI employees and job applicants. ShinyHunters defaced the FBI Jobs website (apply.fbijobs.gov) with their branding and claim to be exploiting the same vulnerability against Fortune 500 companies. The group stated the attack was retaliation for an FBI FLASH report published in May 2026, and they have not ruled out releasing the stolen data.
bleeping-computer ·1w ago
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
The ShinyHunters cybercrime group breached the Clop ransomware gang's data leak site by exploiting an unauthenticated file upload vulnerability in Grav CMS. They defaced the Tor-based site with ASCII art of Umbreon, their logo, and claimed to have stolen server data including source code, system logs, and the private keys for Clop's onion service. ShinyHunters stated they plan to extort Clop and published a message via the compromised site, marking an escalation in an ongoing feud between the two threat groups.
bleeping-computer ·2w ago
Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
Anthropic identified multiple threat actors, dubbed Generative Threat Groups (GTGs), leveraging its Claude AI models to automate cyber attacks, including reconnaissance, exploitation, and data exfiltration. These groups include state-sponsored, financially motivated, and ideologically driven actors from Russia, China, Iran, and elsewhere, conducting operations such as credential harvesting, supply chain compromises, AI model theft, and influence campaigns. Specific activities include exploiting a WordPress re-installation race condition, deploying web shells, stealing API keys, and building surveillance platforms. The report highlights the use of autonomous multi-agent frameworks that operate with minimal human intervention across global victims in government, tech, finance, and political sectors.
hacker-news ·3w ago
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
Microsoft identified two distinct attack campaigns targeting enterprise cloud environments. The first involved a large-scale phishing campaign using CEO impersonation and AI-generated content to trick finance teams into executing fraudulent ACH transfers. The second, more technically sophisticated campaign used social engineering around passkey and MFA updates to compromise Microsoft cloud identities, enabling persistent access through adversary-in-the-middle attacks and abuse of Microsoft Graph API for reconnaissance and data exfiltration. The activity is attributed to multiple threat actor groups, including Storm-3121 and Storm-3032 (UNC6671), with infrastructure linked to known cybercrime collectives.
hacker-news ·2w ago
Passkey-themed phishing attacks lead to Microsoft 365 data theft
Threat actors linked to ShinyHunters, Helix, and other extortion gangs are conducting passkey and single sign-on-themed phishing campaigns to compromise corporate Microsoft 365 accounts. The attacks begin with social engineering via phone or messaging, impersonating IT help desks to trick employees into visiting phishing sites or authorizing device-code authentication, enabling adversary-in-the-middle attacks. Attackers perform extensive reconnaissance using Microsoft Graph, persist by adding attacker-controlled MFA methods, and exfiltrate data from SharePoint, OneDrive, and Exchange over prolonged periods to evade detection.
bleeping-computer ·3w ago