ShinyHunters

APT / StateG1057
Techniques (MITRE ATT&CK)46
Sourceransomware.live
0
Also known as:UNC6240Bling Libra

Vexday analysis

ShinyHunters é um grupo motivado financeiramente, ativo desde 2020, especializado em roubo de dados e extorsão, responsável por violações de alto perfil como Ticketmaster (via Snowflake) e PowerSchool. Em 2025, o grupo lançou uma oferta de Ransomware-as-a-Service denominada "shinysp1d3r", expandindo seu modelo operacional. Em agosto de 2025, autoridades francesas prenderam quatro membros da organização.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity70
Impact: High
T1190T1059.007T1110T1016T1213.003T1567ENTRYInitial accessExploitPublic-Facing App…EXECExecutionJavaScriptCREDCredential accessBrute ForceDISCDiscoverySystem NetworkConfiguration Dis…COLLCollectionCode RepositoriesEXFILExfiltrationExfiltration OverWeb ServiceIMPACTImpactData Destruction

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Exploited vulnerabilities 4

CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.

ShinyHunters uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →