What We Missed: Did ShinyHunters 'Breach' ReliaQuest?
Dark Reading’s “What We Missed” segment explored a complex situation surrounding ShinyHunters and ReliaQuest. Initially, ShinyHunters publicly boasted about breaching ReliaQuest, claiming to have gained access through a spoofed Okta account. However, ReliaQuest disclosed that an employee was phished, and the attacker only gained read-only access to a limited portion of their SSO portal, preventing further damage. The incident highlighted the importance of context when interpreting breach reports, as not all breaches are created equal. Additionally, Palo Alto Networks’ Unit 42 research indicated that AI-generated malware, while increasing in volume, remains largely ineffective in real-world environments due to the complexity of execution and monetization. Finally, the arrest of two alleged Team PCP members, Ruben Ian Thomson and Lewis Michael Gaebler, involved in supply chain attacks, was announced, furthering the investigation into the TeamPCP group’s activities.
In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the latest antics of ShinyHunters to new research about the prevalence (or lack thereof) of AI-generated malware.
ShinyHunters publicly boasted about breaching ReliaQuest, but the claims appear to be mostly hot air.
Last week, ReliaQuest was, I guess, investigating some Shiny Hunters activity. They posted something to Twitter/X about some of the recent social engineering attempts. A threat actor, presumably associated with Shiny Hunters, chimed in and replied to them on social media, on X, and said, "Who's hunting who?" and appeared to have a photo of, I guess, an Okta portal. Turns out that an employee at ReliaQuest did get phished, and the attacker was able to use those credentials to get into something, but not much, it appears. So what'd you think of this story?
Shiny Hunters is often referred to as Shiny Lapsus$ Hunters. And the Lapsus$ part is important because when Lapsus$ popped up, I think it was like 2022, 2023, they were known for doing a lot of these very low-impact breaches where they would either steal some quick source code or get behind the — get in some portal, take a screenshot, do something very low-impact, and then brag about it.
They did some other, more substantial, impressive attacks in addition to that, but that was their MO, I think, for their first few months. And this stinks of a Lapsus$-style attack, where yes, in the loosest of terms, they did breach ReliaQuest if you count through its Okta portal, which I would. But it sounds like nothing really happened. And not to go to bat for a vendor, but what I’ll say as something worth possibly celebrating is that the attackers got credentials, got somewhere they shouldn’t, got to a really sensitive part of a network, and weren’t able to do anything. So I think that's possibly evidence of zero trust working. Cause it's not to say no one should ever get attacked or breached. Everyone always will. But what matters a lot of the time is what happens after you do get breached. And it sounds like, based on ReliaQuest’s own reporting, that it was handled. I don't know. Am I a little too positive on this?
First thing I’ll point out with Shiny Hunters is that Shiny Hunters is often referred to as Shiny Lapsus$ Hunters. And the Lapsus$ part is important because when Lapsus$ popped up, I think it was like 2022, 2023, they were known for doing a lot of these very low-impact breaches where they would either steal some quick source code or get behind the — get in some portal, take a screenshot, do something very low-impact, and then brag about it.
They did some other, more substantial, impressive attacks in addition to that, but that was their MO, I think, for their first few months. And this stinks of a Lapsus$-style attack, where yes, in the loosest of terms, they did breach ReliaQuest if you count through its Okta portal, which I would. But it sounds like nothing really happened. And not to go to bat for a vendor, but what I’ll say as something worth possibly celebrating is that the attackers got credentials, got somewhere they shouldn’t, got to a really sensitive part of a network, and weren’t able to do anything. So I think that's possibly evidence of zero trust working. Cause it's not to say no one should ever get attacked or breached. Everyone always will. But what matters a lot of the time is what happens after you do get breached. And it sounds like, based on ReliaQuest’s own reporting, that it was handled. I don't know. Am I a little too positive on this?
Unit 42, Palo Alto Networks’ research wing. I think they're also sort of the — they're the threat research. They do some, I think they're involved in the incident response too. Anyway, they just did a report on malware enabled by AI, whether that means AI-generated code, AI-themed lures, agentic malware concepts. They analyzed 405 malware samples that they could find.
Only 12 samples were observed on actual production endpoints protected by their Cortex XDR. 97% never appeared in real-world environments. And the 12 samples that were seen in production endpoints, all of them were detected and blocked by existing security controls. And their takeaway—not to speak for either of us, but their takeaway—is that yes, malware or AI is enabling faster malware, but a lot of the controls that already exist in place for mature security organizations still generally work. And it was a lot of vibe-coded ransomware that was in the last 12. What do you think?
Are these the Shai-Hulud folks?
Yeah. A leader.
They might be. I don't know. There was some discussion, debate about who actually created the Shai-Hulud worm, the mini Shai-Hulud. Was it TeamPCP? Is TeamPCP even a thing? It's all murky. I would say that they are definitely involved with some supply chain attacks. It's just sort of triangulating which ones that they're responsible for that might take some time to sort of really hammer down.
Right.
Yeah. A leader.
They might be. I don't know. There was some discussion, debate about who actually created the Shai-Hulud worm, the mini Shai-Hulud. Was it TeamPCP? Is TeamPCP even a thing? It's all murky. I would say that they are definitely involved with some supply chain attacks. It's just sort of triangulating which ones that they're responsible for that might take some time to sort of really hammer down.
Right.
Yeah. A leader.
They might be. I don't know. There was some discussion, debate about who actually created the Shai-Hulud worm, the mini Shai-Hulud. Was it TeamPCP? Is TeamPCP even a thing? It's all murky. I would say that they are definitely involved with some supply chain attacks. It's just sort of triangulating which ones that they're responsible for that might take some time to sort of really hammer down.
Right.
Yeah. A leader.
They might be. I don't know. There was some discussion, debate about who actually created the Shai-Hulud worm, the mini Shai-Hulud. Was it TeamPCP? Is TeamPCP even a thing? It's all murky. I would say that they are definitely involved with some supply chain attacks. It's just sort of triangulating which ones that they're responsible for that might take some time to sort of really hammer down.
Right.
Yeah. A leader.
They might be. I don't know. There was some discussion, debate about who actually created the Shai-Hulud worm, the mini Shai-Hulud. Was it TeamPCP? Is TeamPCP even a thing? It's all murky. I would say that they are definitely involved with some supply chain attacks. It's just sort of triangulating which ones that they're responsible for that might take some time to sort of really hammer down.
Right.
Yeah. A leader.
They might be. I don't know. There was some discussion, debate about who actually created the Shai-Hulud worm, the mini Shai-Hulud. Was it TeamPCP? Is TeamPCP even a thing? It's all murky. I would say that they are definitely involved with some supply chain attacks. It's just sort of triangulating which ones that they're responsible for that might take some time to sort of really hammer down.
Right.
Yeah. A leader.
They might be. I don't know. There was some discussion, debate about who actually created the Shai-Hulud worm, the mini Shai-Hulud. Was it TeamPCP? Is TeamPCP even a thing? It's all murky. I would say that they are definitely involved with some supply chain attacks. It's just sort of triangulating which ones that they're responsible for that might take some time to sort of really hammer down.
Right.
Yeah. A leader.
They might be. I don't know. There was some discussion, debate about who actually created the Shai-Hulud worm, the mini Shai-Hulud. Was it TeamPCP? Is TeamPCP even a thing? It's all murky. I would say that they are definitely involved with some supply chain attacks. It's just sort of triangulating which ones that they're responsible for that might take some time to sort of really hammer down.
Right.
Yeah. A leader.
They might be. I don't know. There was some discussion, debate about who actually created the Shai-Hulud worm, the mini Shai-Hulud. Was it TeamPCP? Is TeamPCP even a thing? It's all murky. I would say that they are definitely involved with some supply chain attacks. It's just sort of triangulating which ones that they're responsible for that might take some time to sort of really hammer down.
Right.
Yeah. A leader.
They might be. I don't know. There was some discussion, debate about who actually created the Shai-Hulud worm, the mini Shai-Hulud. Was it TeamPCP? Is TeamPCP even a thing? It's all murky. I would say that they are definitely involved with some supply chain attacks. It's just sort of triangulating which ones that they're responsible for that might take some time to sort of really hammer down.
Right.
Yeah. A leader.
They might be. I don't know. There was some discussion, debate about who actually created the Shai-Hulud worm, the mini Shai-Hulud. Was it TeamPCP? Is TeamPCP even a thing? It's all murky. I would say that they are definitely involved with some supply chain attacks. It's just sort of triangulating which ones that they're responsible for that might take some time to sort of really hammer down.
Right.
Yeah. A leader.
They might be. I don't know. There was some discussion, debate about who actually created the Shai-Hulud worm, the mini Shai-Hulud. Was it TeamPCP? Is TeamPCP even a thing? It's all murky. I would say that they are definitely involved with some supply chain attacks. It's just sort of triangulating which ones that they're responsible for that might take some time to sort of really hammer down.
Right.
Yeah. A leader.
They might be. I don't know. There was some discussion, debate about who actually created the Shai-Hulud worm, the mini Shai-Hulud. Was it TeamPCP? Is TeamPCP even a thing? It's all murky. I would say that they are definitely involved with some supply chain attacks. It's just sort of triangulating which ones that they're responsible for that might take some time to sort of really hammer down.
Right.
Yeah. A leader.
They might be. I don't know. There was some discussion, debate about who actually created the Shai-Hulud worm, the mini Shai-Hulud. Was it TeamPCP? Is TeamPCP even a thing? It's all murky. I would say that they are definitely involved with some supply chain attacks. It's just sort of triangulating which ones that they're responsible for that might take some time to sort of really hammer down.
Right.
Yeah. A leader.
They might be. I don't know. There was some discussion, debate about who actually created the Shai-Hulud worm, the mini Shai-Hulud. Was it TeamPCP? Is TeamPCP even a thing? It's all murky. I would say that they are definitely involved with some supply chain attacks. It's just sort of triangulating which ones that they're responsible for that might take some time to sort of really hammer down.
Right.
Yeah. A leader.
They might be. I don't know. There was some discussion, debate about who actually created the Shai-Hulud worm, the mini Shai-Hulud. Was it TeamPCP? Is TeamPCP even a thing? It's all murky. I would say that they are definitely involved with some supply chain attacks. It's just sort of triangulating which ones that they're responsible for that might take some time to sort of really hammer down.
