Mandiant details how ShinyHunters abuse SSO to steal cloud data
ID: a2c94875-724e-543e-96f1-3fcd0f6159f5
STIX ID: report--a2c94875-724e-543e-96f1-3fcd0f6159f5
Feed Name: Bleeping Computer
Mandiant and Google Threat Intelligence report that ShinyHunters and affiliated clusters (UNC6661, UNC6671, UNC6240) conduct targeted vishing attacks combined with advanced phishing kits to steal SSO credentials and MFA codes, enroll attacker MFA devices, pivot into Okta/Microsoft Entra/Google SSO dashboards and mass-exfiltrate SaaS data (Salesforce, M365, SharePoint, DocuSign, etc.) for extortion; the report includes observed IOCs, phishing domain naming patterns, examples of logs, and recommended hardening and detection controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
