ShinyHunters is a hacker group that has been active since 2019. The group is decentralized and internationally distributed, with no confirmed nation-state affiliation. ShinyHunters is financially motivated and operates under a “pay or leak” extortion model; Meaning that they steal data, demand a ransom, and if the victim doesn’t pay, the data gets sold on dark web forums or leaked publicly. While some members have been arrested, that has not stopped ShinyHunters from working their way to be one of the most prolific hacker groups.

Attacks Performed

ShinyHunters is responsible for multiple high-profile cyberattacks. ShinyHunters do not target a specific sector, but rather go for companies that they can profit largely from. ShinyHunters has breached Canvas, ADT, Snowflake , and other large corporations. Many of these breaches have resulted in the target’s data being posted online for other malicious actors to utilize.

Common Attack Vectors:

Some Common Attack Vectors that ShinyHunters employ are:

  1. Voice phishing (vishing)
  2. OAuth token theft
  3. Cloud misconfigurations
  4. GitHub/repo scraping
  5. Supply chain attacks

These Attack Vectors are some of the more common ways ShinyHunters can infiltrate your network, but they are not the only way. ShinyHunters has also been known to exploit zero-day vulnerabilities to compromise networks. As the threat landscape evolves, ShinyHunters will as well, causing for more intricate and sophisticated breaches.

What SHQ Brings

SecurityHQ’s Threat and Risk Intelligence Service has multiple offerings that can help identify malicious actors, like ShinyHunters, from utilizing your data on the dark web.

Dark Web Monitoring is offered to detect leaked credentials or private information for sale. The Vendor Breach Intelligence offering allows SecurityHQ to monitor your third parties to ensure no breaches or shared data becomes available on the dark web.

SecurityHQ’s MDR Service offers Security Performance Engineering to proactively increase your cybersecurity posture and enable you to be as secure as possible against incoming threats like ShinyHunters.

General Advice

Enhancements you can make to combat the Threat Vectors that ShinyHunters utilize:

  • Assess Third Party Risk: Require a security questionnaire to be answered for all third party vendors
  • Cybersecurity Awareness Program: Conduct phishing campaigns to help users identify social engineering attacks
  • Enforce MFA: Ensure MFA is enforced in all location that it can be
  • Limit Vendor access: Enforce the principle of least privilege on third party accounts
  • Monitor anomalies via SIEM/XDR tooling: Utilize a SIEM/XDR to correlate signals into actionable alerts to investigate