Home Cyber Security News Google Warns Of Major Expansion In ShinyHunters Operations Using New Attack Techniques

Google Warns Of Major Expansion In ShinyHunters Operations Using New Attack Techniques

0
Google Flags ShinyHunters Expansion
Google Flags ShinyHunters Expansion

Google’s Threat Intelligence Group (GTIG) and Mandiant have spotted a big rise in attacks linked to the ShinyHunters extortion group.

These cybercriminals use voice phishing (vishing) calls and fake login sites to steal single sign-on (SSO) credentials and multi-factor authentication (MFA) codes from employees.

Once inside company networks, they grab sensitive data from cloud apps like SharePoint, Salesforce, and DocuSign. Then, they demand ransom or leak the info on dark web sites.

This is not due to flaws in vendor software. It’s pure social engineering. GTIG tracks it under clusters UNC6661, UNC6671, and UNC6240.

The attacks hit more cloud platforms now, showing ShinyHunters wants richer data for bigger payoffs. They’ve added nasty tricks like harassing victims and DDoS attacks on company sites.

Vishing and Credential Theft Tactics

Threat actors pose as IT help desk staff. They call workers, claim MFA updates are needed, and send them to fake sites like <company>sso.com or <company>internal.com.

These domains often come from registrars like NICENIC or Tucows. Victims enter SSO logins and MFA codes, letting attackers register their own devices.

UNC6661 struck in early January 2026. They hit Okta users, then roamed to SaaS apps.

{
  "AppAccessContext": {
    "AADSessionId": "[REDACTED_GUID]",
    "AuthTime": "1601-01-01T00:00:00",
    "ClientAppId": "[REDACTED_APP_ID]",
    "ClientAppName": "Microsoft Office",
    "CorrelationId": "[REDACTED_GUID]",
    "TokenIssuedAtTime": "1601-01-01T00:02:56",
    "UniqueTokenId": "[REDACTED_ID]"
  },
  "CreationTime": "2026-01-10T13:17:11",
  "Id": "[REDACTED_GUID]",
  "Operation": "FileDownloaded",
  "OrganizationId": "[REDACTED_GUID]",
  "RecordType": 6,
  "UserKey": "[REDACTED_USER_KEY]",
  "UserType": 0,
  "Version": 1,
  "Workload": "SharePoint",
  "ClientIP": "[REDACTED_IP]",
  "UserId": "[REDACTED_EMAIL]",
  "ApplicationId": "[REDACTED_APP_ID]",
  "AuthenticationType": "OAuth",
  "BrowserName": "Mozilla",
  "BrowserVersion": "5.0",
  "CorrelationId": "[REDACTED_GUID]",
  "EventSource": "SharePoint",
  "GeoLocation": "NAM",
  "IsManagedDevice": false,
  "ItemType": "File",
  "ListId": "[REDACTED_GUID]",
  "ListItemUniqueId": "[REDACTED_GUID]",
  "Platform": "WinDesktop",
  "Site": "[REDACTED_GUID]",
  "UserAgent": "Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.20348.4294",
  "WebId": "[REDACTED_GUID]",
  "DeviceDisplayName": "[REDACTED_IPV6]",
  "EventSignature": "[REDACTED_SIGNATURE]",
  "FileSizeBytes": 31912,
  "HighPriorityMediaProcessing": false,
  "ListBaseType": 1,
  "ListServerTemplate": 101,
  "SensitivityLabelId": "[REDACTED_GUID]",
  "SiteSensitivityLabelId": "",
  "SensitivityLabelOwnerEmail": "[REDACTED_EMAIL]",
  "SourceRelativeUrl": "[REDACTED_RELATIVE_URL]",
  "SourceFileName": "[REDACTED_FILENAME]",
  "SourceFileExtension": "xlsx",
  "ApplicationDisplayName": "Microsoft Office",
  "SiteUrl": "[REDACTED_URL]",
  "ObjectId": "[REDACTED_URL]/[REDACTED_FILENAME]"
}

Logs show downloads from SharePoint via PowerShell, Salesforce logins from suspicious IPs, and DocuSign envelope grabs.

In one case, they turned on ToogleBox Recall in Google Workspace to delete Okta’s “new MFA device” emails, hiding their tracks.

UNC6671 used similar vishing but different domain registrars. They also pulled SharePoint data with PowerShell.

After theft, UNC6661 sent phishing emails from stolen accounts to crypto firms, then deleted them. UNC6240 handles extortion, using Tox chats, BTC demands, and LimeWire samples.

A new “SHINYHUNTERS” leak site lists victims with emails like shinycorp@tutanota.com.

Phishing Domain PatternsExamples (Defanged)
Corporate SSO<company>sso[.]com, my<company>sso[.]com
Internal Portals<company>internal[.]com, www.<company>internal[.]com
Support/Helpdesk<company>support[.]com, support-<company>[.]com
Identity Providers<company>okta[.]com, <company>azure[.]com
Access Portal<company>access[.]com, my<company>access[.]com

Data Exfiltration and Extortion Escalation

Attackers search cloud apps for keywords like “poc,” “confidential,” “salesforce,” or “vpn.” They target PII in Salesforce and Slack chats.

Extortion notes give 72-hour deadlines, BTC addresses, and threats. UNC6671 skips ShinyHunters branding but harasses staff.

Ransom note extract (Source: Google Cloud)

IPs tie to VPNs like Mullvad, Oxylabs, and proxies. Google added phishing domains to Chrome Safe Browsing.

Key Network IOCsASNAssociation
24.242.93[.]12211427UNC6661
73.135.228[.]9833657UNC6661
76.64.54[.]159577UNC6671
142.127.171[.]133577UNC6671

Switch to phishing-resistant MFA like FIDO2 keys or passkeys. They beat SMS or push alerts.

Monitor Okta for admin role changes from anonymized IPs, SharePoint bulk downloads via PowerShell, and ToogleBox auths.

Google Security Operations has rules like “Okta Suspicious Actions from Anonymized IP” and SharePoint high-volume queries.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here