Threat Group 'Bling Libra' Pivots to Extortion for Cloud Attacks
ID: be9d1bfa-9bbd-5b5f-a3d4-42a5b71417b3
STIX ID: report--be9d1bfa-9bbd-5b5f-a3d4-42a5b71417b3
Feed Name: Dark Reading
Date Published: 2024-08-27
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Unit 42 researchers report that the Bling Libra (ShinyHunters) group has evolved from selling stolen data to using double-extortion tactics against cloud environments: attackers harvest exposed or weak credentials (often lacking MFA), access AWS/S3 resources to exfiltrate and delete data, then threaten publication unless a ransom is paid; the report details an investigated incident, ties to large breaches (including Ticketmaster), and recommends MFA, least-privilege IAM, and enhanced logging and monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
