logo

Bling Libra’s Tactical Evolution: The Threat Actor Group Behind ShinyHunters Ransomware

ID: 29efcfdc-a997-52e0-aac2-3526056c3668

STIX ID: report--29efcfdc-a997-52e0-aac2-3526056c3668

Feed Name: Palo Alto Networks Unit 42

Threat Score
70/100

Date Published: 2024-08-23

Date Updated: 2026-04-28

Author: Margaret Zimmermann and Chandni Vaya

...
...

Unit 42 investigated a Bling Libra (ShinyHunters) incident in which the actor harvested exposed AWS access keys, used them to access and enumerate S3 buckets using AWS CLI, S3 Browser, and WinSCP, deleted a subset of buckets, and then sent an extortion demand; the report details the CloudTrail API calls produced by those tools, provides IoCs (user-agents and an email), and recommends AWS hardening measures (least privilege, logging, GuardDuty, Config, MFA for sensitive S3 actions).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.