>samit_hota
Back to adversary profiles

Threat Actor Dossier

Threat Actor Profile: ShinyHunters (UNC6240 / Bling Libra)

G1057

Also tracked as UNC6240 · Bling Libra · 6 sectors targeted

Threat level
CRITICAL
Status
ACTIVE
Origin
France / International
Motivation
Financial Gain · Extortion
Samit Hota·
Target Sectors
E-Commerce, Financial Services, Technology, Telecommunications, Entertainment, Retail
Associated Malware
Rclone, AWS CLI, Lumma Stealer, Vidar Stealer, Custom Python Scripts
#threat-actor#g1057

Few cybercriminal groups have disrupted enterprise cloud environments as persistently as ShinyHunters. Also tracked under aliases such as UNC6240 and Bling Libra, this financially motivated threat collective specializes in cloud environment intrusions, large-scale database theft, and high-profile dark web extortion. Since emerging around 2020, ShinyHunters has evolved from publishing stolen consumer databases on illicit forums into a central pillar of the modern cybercrime ecosystem.

Overview & Ecosystem Ties

ShinyHunters first gained widespread notoriety by stealing and leaking massive databases from e-commerce, gaming, and technology firms, including Tokopedia, Wattpad, Wishbone, and Microsoft GitHub repositories. While early operations were primarily attributed to a loose collective of Western threat actors—highlighted by the 2023 arrest and subsequent sentencing of French national Sebastien Raoult (“Seker”)—the group has proven resilient to law enforcement actions.

The group operates at the intersection of several prominent cybercrime networks. ShinyHunters maintains deep ties to “The Com,” a decentralized community of predominantly English-speaking threat actors known for SIM swapping, voice phishing (vishing), and aggressive social engineering. This ecosystem overlap has led to fluid operational partnerships, commonly reflected in joint campaigns with groups like Scattered Spider (UNC3944) and LAPSUS$. In security circles, these joint operations are frequently referred to by combined designations such as “Scattered Lapsus Shiny Hunters” (SLSH).

Beyond their role as breach operators, ShinyHunters effectively controls major infrastructure within the cybercrime underground. Following law enforcement takedowns of BreachForums in 2023, ShinyHunters stepped in to administer subsequent iterations of the site, establishing themselves as key brokers for stolen corporate data, zero-day disclosures, and initial access sales.

Campaign Evolution & High-Profile Targets

The group’s targets span a broad spectrum of industries, but their core operational focus remains consistent: high-volume data repositories containing personally identifiable information (PII), customer payment records, and corporate credentials.

  • Early Data Leaks (2020–2022): ShinyHunters systematically targeted public-facing cloud databases, exposed Amazon S3 buckets, and private code repositories. Victims included major platforms across e-commerce, mobile applications, and online media, resulting in hundreds of millions of stolen user records posted or sold online.
  • SaaS and OAuth Exploitation (2023): As defense perimeter security improved, ShinyHunters shifted heavily toward corporate SaaS ecosystems, targeting platforms like Salesforce, Google Workspace, and cloud identity providers. By compromising third-party integration tokens and administrative access, they bypassed standard network perimeters.
  • Snowflake & Cloud Storage Extortion (2024): In one of the most widespread cloud extortion campaigns in recent memory, ShinyHunters—in collaboration with affiliate threat actors—targeted hundreds of corporate cloud data warehouses hosted on Snowflake. By exploiting credentials previously harvested by infostealer malware (such as Lumma and Vidar) from unmanaged employee and contractor devices, the group breached environments that lacked multi-factor authentication (MFA). High-profile victims included Live Nation/Ticketmaster, Santander Bank, and Advance Auto Parts.

Tactics, Techniques, and Procedures (TTPs)

ShinyHunters rarely relies on bespoke malware or sophisticated zero-day exploits. Instead, their operations are defined by identity theft, social engineering, and the abuse of legitimate administrative utilities (“living off the cloud”).

  • Initial Access: Access is primarily achieved through credential stuffing using infostealer dumps, targeted vishing (calling help desks or employees to trick them into transferring MFA tokens or resetting credentials), and SIM swapping key personnel. They also actively buy access tokens and credentials from initial access brokers (IABs).
  • Persistence & Privilege Escalation: Once inside an environment, ShinyHunters creates secondary administrative accounts, generates new API keys, or registers malicious OAuth applications to maintain persistent access even if password resets are enforced.
  • Defense Evasion: By leveraging valid credentials and native protocols, their activity often blends in with standard administrator traffic. They routinely disable logging services within compromised cloud tenants or operate out of non-standard geographic regions via residential proxy networks.
  • Exfiltration: Exfiltration relies heavily on standard open-source or native cloud utilities. Tools like rclone, the AWS Command Line Interface (awscli), Snowflake bulk unload utilities, and custom Python exfiltration scripts are used to rapidly copy structured database tables to attacker-controlled cloud storage.

Monetization & Extortion Methods

ShinyHunters employs a dual-revenue strategy: double extortion and direct data monetization. Upon exfiltrating a target’s database, they issue extortion demands via encrypted messaging platforms (such as Telegram) or professional email services. If the victim refuses to negotiate or pay a ransom—typically demanded in Bitcoin or Monero—ShinyHunters monetizes the stolen assets by:

  1. Auctioning Data: Offering exclusive rights to the database on BreachForums or private Telegram channels.
  2. Public Leaks: Releasing the data incrementally to build public pressure on the victim.
  3. Secondary Targeting: Selling credential dumps to other threat actors who use the data for credential stuffing or targeted phishing campaigns against the victim’s customer base.

Current Status & Threat Outlook

ShinyHunters remains highly active and represents a top-tier threat to enterprise cloud environments. The group’s administration of BreachForums provides them with both high status in the criminal underground and direct monetization channels for their breaches.

Their operational pivot toward identity-based attacks on cloud data warehouses demonstrates that organizations cannot rely solely on infrastructure security; robust identity governance, mandatory MFA for all cloud tenants, explicit session control policies, and continuous monitoring of third-party SaaS integrations are critical to mitigating the threat posed by ShinyHunters.

Worried this actor targets your sector?

Let's map your exposure before they find it themselves.

Book an advisory call