ShinyHunters

THREAT ACTOR PROFILE

ShinyHunters

ShinyHunters

ShinyHunters

ShinyHunters is a financially motivated data-theft and extortion brand that emerged in 2020. It has grown from stealing exposed credentials into a loose collective that compromises SaaS platforms through voice phishing and OAuth abuse, then pressures victims to pay or see their data leaked.

Not attributed

Business / Finance / Education

First seen

2020

Latest IOC

-

IP indicators

Hosts

SHA256 hashes

Posts

NAMES AND ALIASES

A brand several intrusion clusters operate under

ShinyHunters works less like a single team and more like a brand. Sekoia's reporting describes extortion and data-broker activity carried out by different intrusion clusters, which is why Mandiant uses several UNC numbers for the underlying work.

The names below map to one entry in our list of known threat actors, so a Bling Libra writeup and a UNC6240 advisory read as one story.

-

-

-

GROUP PROFILE

An extortion brand built on stolen SaaS data

ShinyHunters started with large data breaches of companies like Tokopedia, AT&T and Ticketmaster, selling the data on forums such as BreachForums. It has since shifted toward extortion and now aligns with the Scattered Lapsus$ Hunters collective.

Our record ties it to the Bling Libra activity and places its victims across business, financial services and education, with incidents in the US, Canada, Spain, Chile and Uruguay. Sekoia's 2026 reporting describes a modular division of labor where different clusters handle intrusions while the brand handles extortion.

The group's strength is attacking trust and authentication rather than software. Vishing, OAuth consent abuse and SaaS supply-chain access let it steal large volumes of data without malware, though a 2026 Oracle PeopleSoft campaign added real exploitation.

Facts:

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Victims reported in our records and posts:

-

-

-

-

-

-

-

-

-

ATTACK LIFECYCLE

Phone the help desk, or exploit PeopleSoft

The stages below come from 2026 ShinyHunters activity documented in posts we track on our IOC Hunter feed.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

MALWARE AND TOOLING

MeshCentral, SIDEEYE and a ransomware spin-off

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

CVES EXPLOITED

One critical Oracle PeopleSoft flaw

CVE-2026-21509

A Microsoft Office security bypass used to open the fileless chain in Operation Neusploit, and again in the PixyNetLoader intrusion chain. Both campaigns paired the exploit with spear-phishing from compromised accounts rather than mass exploitation.

ShinyHunters

IOCS FROM HUNT.IO PLATFORM

Latest IOCs

We currently track - IP indicators, - hosts, and - SHA256 hashes for Akira across - intelligence posts, with the most recent indicator dated -. The sample below is limited to indicators from the latest posts. It is not the full set.

ShinyHunters

Hosting Company

IPs

Date

Hosting Company

IPs

Date

144.126.202.227

LameHug exfil

06-17

Showing a sample of recent indicators

Get the complete

ShinyHunters

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

ShinyHunters

IOC set, full IP, host and hash history.

NOTABLE CAMPAIGNS

From Salesforce OAuth abuse to PeopleSoft RCE

The 2026 reporting tracks a group moving from pure social engineering into mass exploitation, while keeping extortion at the center.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

Showing a sample of recent indicators

Get the complete

ShinyHunters

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

ShinyHunters

IOC set, full IP, host and hash history.