SophiaX
🔍
LIVE
· New victim: Portable Intelligence Inc www.portable-intelligence.com serviced by an IT company Computer... — blacknevas· New victim: Riker Danzig Scherer Hyland & Perretti — SilentRansomGroup· New victim: Hightech Signs — kairos· New victim: Riker Danzig LLP — SilentRansomGroup· New victim: gamaus.com — incransom· New KEV: CVE-2026-72898 · Metabase· New KEV: CVE-2026-20349 · Cisco· New KEV: CVE-2026-68820 · Microsoft· New KEV: CVE-2026-8037 · Progress· New KEV: CVE-2026-63077 · JetBrains· New victim: 3,979 new IOCs ingested in last 24h Portable Intelligence Inc www.portable-intelligence.com serviced by an IT company Computer... — blacknevas· New victim: Riker Danzig Scherer Hyland & Perretti — SilentRansomGroup· New victim: Hightech Signs — kairos· New victim: Riker Danzig LLP — SilentRansomGroup· New victim: gamaus.com — incransom· New KEV: CVE-2026-72898 · Metabase· New KEV: CVE-2026-20349 · Cisco· New KEV: CVE-2026-68820 · Microsoft· New KEV: CVE-2026-8037 · Progress· New KEV: CVE-2026-63077 · JetBrains· 3,979 new IOCs ingested in last 24h

ShinyHunters

❔ UnknownMotivation: financialLast active: 2026-08-02First seen: 2026-04-12G1057
0
linked CVEs
Also known as
UNC6240Bling Libra
Targeted industries
Agriculture and Food ProductionBusiness ServicesConsumer ServicesEducationEnergyFinancial ServicesHealthcareHospitality and TourismManufacturingNot FoundTechnologyTelecommunicationTransportation/Logistics
Targeted regions
CACODEESFRGBNLSGUS
ShinyHunters is a cybercriminal group of unknown origin that is motivated by financial gain. The group is known for its sophisticated attacks against a wide range of targets, including businesses, organizations, and government agencies. ShinyHunters typically uses phishing attacks and exploit kits to gain access to victim networks, where they deploy malware to steal sensitive data, such as names, addresses, phone numbers, Social Security numbers, and credit card information.
Source: misp_galaxy · Collected: 2026-08-08
⚡ Vulnerabilities & Exploits0 CVEs
threat_actor_cve → cves / exploits.cve_ids
No CVE correlation on record for this actor yet.
🔍 Detection Coverage0 Sigma
Derived from linked CVEs — not a direct actor match
No Sigma rules mapped via this actor's CVEs yet.
🧬 YaraComing soon
MITRE ATT&CK Techniques Used46 techniques
Across 14 tactics
Collection4 techniques
Command And Control4 techniques
Discovery7 techniques
T1016System Network Configuration Discovery
Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems. Several opera…
T1018Remote System Discovery
Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system. Functionality…
T1069.003Cloud Groups
Adversaries may attempt to find cloud groups and permission settings. The knowledge of cloud permission groups can help adversaries determine the particular roles of users and groups within an environ…
T1082System Information Discovery
An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this informatio…
T1083File and Directory Discovery
Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from [F…
T1580Cloud Infrastructure Discovery
An adversary may attempt to discover infrastructure and resources that are available within an infrastructure-as-a-service (IaaS) environment. This includes compute service resources such as instances…
T1619Cloud Storage Object Discovery
Adversaries may enumerate objects in cloud storage infrastructure. Adversaries may use this information during automated discovery to shape follow-on behaviors, including requesting all or specific ob…
Execution4 techniques
Initial Access5 techniques
Reconnaissance5 techniques
Resource Development6 techniques
Stealth5 techniques
🛰️ Infrastructure & IOCs6
ip138.226.246.942026-07-14
ip212.86.125.242026-07-14
ip94.154.32.1602026-07-14
ip213.111.148.902026-07-14
ip103.75.11.782026-07-14
ip103.75.11.1102026-07-14
📰 Threat Intel Coverage7
Digest reports mentioning this actor (incl. aliases)
Hackers Breached Klue Integration to Steal Salesforce CRM Data via OAuth Tokensmatched as ShinyHunters2026-06-19
Canvas login portals hacked in mass ShinyHunters extortion campaignmatched as ShinyHunters2026-05-08
Okta Vishing Campaign Linked to ShinyHunters Bypasses Multi-Factor Authenticationmatched as ShinyHunters2026-01-30
ShinyHunters Claims Theft of 1.5 Billion Salesforce Recordsmatched as ShinyHunters2025-09-19
Cloudflare Confirms Salesforce Data Compromised via Salesloft Chatbotmatched as ShinyHunters2025-09-07
Google Among Victims in Ongoing Salesforce Data Theft Campaignmatched as ShinyHunters2025-08-08
Arrest of BreachForums v2 Operators in Francematched as ShinyHunters2025-06-30