Shiny Hunters at Work Again!

 Some recent news is coming out about an ongoing wave of voice-phishing or “vishing.”  The threat actor is identified as “Shiny Hunters” which was involved in more than 700 Salesforce customer environments last fall.  Mandiant is heavily involved in tracking this new campaign.  It seems the new campaign is focused on compromising SSO credentials from victim organizations and then utilizing that access to enroll the threat actors’ devices into the victim’s multi-factor solutions.

Mandiant advised that this is an ongoing and very active campaign.  Once the TA gains access, they pivot into SaaS environments to exfiltrate data.  It was also noted that once they have the data, ShinyHunters contacts the victim organizations with extortion demands. 

Okta, which is one of the TA’s targets has released some Indicators of Compromise and other details, however those are only available to Okta customers.  You can find the link here:  https://security.okta.com/product/okta/vishing-operators-synchronize-phishing-sites-to-their-script-for-hybrid-social-engineering-attacks.  Please take advantage of any IOC’s that are being released to update your security tools and posture.

You can also find different IOCs at the following IC3 site:  https://www.ic3.gov/CSA/2025/250912.pdf.  These are from September 2025 but could be useful in threat hunting to ensure you were not previously targeted by Shiny Hunters. 

Ensure your employees are aware of this ongoing attack vector and how to report and deal with possible vishing attacks.  These are growing in popularity among the threat actor groups and should be a part of all training programs!

It was also noted last year that Shiny Hunters had combined their forces with Scattered Lapsus$, another active and successful threat group. 

UPDATE: Silent Push has released an updated blog with some new information, including a link to possible victims of this ongoing attack. Please read it here: https://www.silentpush.com/blog/slsh-alert/.

  Source:  https://cyberscoop.com/shinyhunters-voice-phishing-sso-okta-mfa-bypass-data-theft/

Leave a Reply

Discover more from Dave Does Cyber Security

Subscribe now to keep reading and get access to the full archive.

Continue reading