Well, in a week that started off bad, it would seem things just keep getting worse! What do I mean!? Well, not only do we have the NPM packaging leak going on, but now Cisco is alleged to have been breach by ShinyHunters! In fact, the threat actor claims to have breached Salesforce Aura and AWS accounts, totally over 3 million Salesforce records!
These include PII, Github repositories, AWS buckets and other internal corporate data having been compromised! It seems that the threat actor gave Cisco until April 3rd to reply to them or they will leak the sensitive data into the wild!

What does this mean to the customer? Well, many things. Your data could be compromised. Cisco products could be compromised.
It would behoove customers utilizing Cisco products to increase their security awareness and begin to identify and monitor for threats that could arise out of this breach. We have seen far more supply chain breaches recently than in the past and these all present a direct threat, not just to the original victim, but also to their customers.
ShinyHunters is a criminal threat actor group that has been active since 2020 and have been involved in several high-profile breach incidents. They utilize dark web sites for communications and to leak the data they have stolen from their victims.
Below are some IOC’s that are strongly associated with this threat actor. Utilize them to improve your cyber security posture and prevent possible future attacks! Also, please monitor the ongoing Cisco leak case so that you can respond effectively and quickly to any data leak that could compromise their customers or their products.
Indicators of Compromise (IOC)
Phishing infrastructure assessed with high confidence as very likely linked to ShinyHunters:
191[.]96[.]207[.]179
196[.]251[.]83[.]162
163[.]5[.]210[.]210
94[.]156[.]167[.]237
23[.]94[.]126[.]63
198[.]244[.]224[.]200
admiring-shockley[.]196-251-83-162[.]plesk[.]page
bless-invite[.]com
get-carrot-zoom[.]com
modernatx-zoom[.]com
recurly-zoom[.]com
Evilginx Phishing infrastructure assessed with high confidence as very likely linked to Scattered Spider, this assessment is done by infrastructure similarities on previously attributed domains by Silent Push :
sharepoint-comcast[.]com
workday-nike[.]com
workday-hubspot[.]com
sharepoint-workplaceview[.]com
newscorp-okta[.]com
corporate-microsoft[.]com
okta-louisvuitton[.]com
corporate-okta[.]com
pure-okta[.]com
morningstar-okta[.]com
sts-vodafone[.]com
corp-hubspot[.]com
signin-okta[.]com
bmcorpuser.internal-okta[.]com
help-allvuesystems[.]com
allvuesystems-okta[.]com
163[.]5[.]169[.]142
Sha-256 Hash of Okta phishing theme:
0383c0d109b7cfdef058b0197125c85d276510724be33a746056f9a7c181d761
e5c5617c8676e9a5cf6108d344fe7fcb6590671efd6baccb02b9313da0f0d289
36de93aaf26727f6dd55ff2100b08dfb52abccfb57a7bf4d07a7fb703a86623d
6aa51de51a6b352fd073b5b9080011d358d42fa190a8a9ee216e3ef6e657b801
4e20f2c4c90e3654a8c43fb10003978d61d2b48426414dede3b1bd5a2c891b54
qTox ID owned by ShinyCorp:
BD1B683FD3E6CB094341317A4C09923B7AE3E7903A6CDB90E5631EC7DC1452636FF35D9F5AF2
Cryptocurrency Address owned by ShinyCorp:
- Bitcoin Address: bc1q5530apqz86eywm2f84mpcyuux3dv9mmztsdxt2
- XMR Address: 87cEqA6PunENHwe5h8XtRifWuDhNQXKwzGNSbwKmrdEehY4wjRjWvZmSgE8LHTe6e5Pmnuyyiu5AWbGCC9gHUzUj5KHnSH9
Leave a Reply