news.mlab.sh
Threat intelligence
Threat actor

ShinyHunters

Profile from actors.mlab.sh, coverage from our own index.

First seen
2020-01-01 00:00:00
Motivation
Financial gain
TLP
WHITE

(ZeroFOX) ShinyHunters is taking a page out of the book of Gnosticplayers, the breach data broker who in 2018-2019 pilfered billions of records from dozens of companies and sold them online. Due to the verification of the Tokopedia breach by multiple researchers and the company itself, ZeroFOX Alpha Team has HIGH confidence that these new breaches are legitimate, and will most likely be available on other breach marketplaces at lower prices in the near future. It is likely that this actor will continue to breach companies and post their content for sale. These tactics proved both successful and profitable for gnosticplayers, and it is likely they will continue to appeal to other breach brokers for these reasons. Around July 2025, ShinyHunters teamed up or merged with Subgroup: Scattered Spider. They share their Telegram channel also with Lapsus$, so they may all work together now – see the DataBreaches.net references in the Information section below.

Also known as

Bling LibraShinyHuntersUNC6240

Vulnerabilities exploited

Tooling and malware

Tor

MITRE ATT&CK techniques

T1530 Data from Cloud StorageT1105 Ingress Tool TransferT1219 Remote Access ToolsT1110 Brute ForceT1528 Steal Application Access TokenT1016 System Network Configuration DiscoveryT1018 Remote System DiscoveryT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1580 Cloud Infrastructure DiscoveryT1619 Cloud Storage Object DiscoveryT1072 Software Deployment ToolsT1203 Exploitation for Client ExecutionT1567 Exfiltration Over Web ServiceT1485 Data DestructionT1657 Financial TheftT1190 Exploit Public-Facing ApplicationT1210 Exploitation of Remote ServicesT1598 Phishing for InformationT1078 Valid AccountsT1684 Social Engineering

Coverage 44