ShinyHunters Ransomware Targeting Cloud Environments (Campaign)
ID: baa8b456-a360-5a25-93da-ed7eed3d6a0d
STIX ID: report--baa8b456-a360-5a25-93da-ed7eed3d6a0d
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-08-23
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Bling Libra (ShinyHunters) gained access to an organization's AWS environment by harvesting credentials from an exposed file in a public repository, used tools such as S3 Browser and WinSCP to enumerate and access S3 buckets (generating CloudTrail events like ListBuckets and GetObject), deleted selected buckets, created mock buckets via scripts, and issued a ransom demand; limited IAM permissions prevented full IAM discovery and made it impossible to determine the full extent of potential data exfiltration due to logging gaps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
