Bling Libra’s Tactical Evolution: The Threat Actor Group Behind ShinyHunters Ransomware
ID: 29efcfdc-a997-52e0-aac2-3526056c3668
STIX ID: report--29efcfdc-a997-52e0-aac2-3526056c3668
Feed Name: Palo Alto Networks Unit 42
Date Published: 2024-08-23
Date Updated: 2026-04-28
Author: Margaret Zimmermann and Chandni Vaya
Unit 42 investigated a Bling Libra (ShinyHunters) incident in which the actor harvested exposed AWS access keys, used them to access and enumerate S3 buckets using AWS CLI, S3 Browser, and WinSCP, deleted a subset of buckets, and then sent an extortion demand; the report details the CloudTrail API calls produced by those tools, provides IoCs (user-agents and an email), and recommends AWS hardening measures (least privilege, logging, GuardDuty, Config, MFA for sensitive S3 actions).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
