logo

ShinyHunters Calling: Financially Motivated Data Extortion Group Targeting Enterprise Cloud Applications

ID: 21ae975a-1d8a-5ac1-b001-c0ecbbc80bfe

STIX ID: report--21ae975a-1d8a-5ac1-b001-c0ecbbc80bfe

Feed Name: EclecticIQ

Threat Score
85/100

Date Published: 2025-09-22

Date Updated: 2026-04-27

Author: Arda Büyükkaya

...
...

EclecticIQ attributes a coordinated eCrime campaign to the ShinyHunters group (led by persona ShinyCorp) that combines AI-driven vishing (outsourced to Scattered Spider and The Com affiliates), insider recruitment, phishing of SSO/Okta and Salesforce, exploitation of Oracle Access Manager (CVE-2021-35587), and theft of BrowserStack API keys to enable CI/CD and supply-chain compromise; the group is actively extorting victims with multi-million-dollar data sale demands, shares indicators (IPs, domains, hashes, wallet addresses), and is developing a RaaS variant targeting VMware ESXi environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.