Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Defending SaaS-based applications against ShinyHunters OAuth abuse

212.86.125.24

TLP:CLEAR
Active

IPv4 Address

Description

Between mid-2025 and mid-2026, threat actors using tradecraft associated with ShinyHunters targeted customer SaaS applications, particularly Salesforce instances, through three primary intrusion paths. Voice phishing campaigns impersonated IT support to trick employees into authorizing malicious OAuth applications. Supply chain compromises leveraged trusted integrations including Salesloft, Gainsight, and Klue to obtain OAuth tokens for downstream customer access. Misconfigured guest access enabled exploitation of Aura framework functionality for unauthorized data queries. These techniques abused legitimate OAuth relationships to inherit user and application privileges, enabling enumeration and exfiltration of CRM data while evading authentication detections. The campaigns targeted multiple industries including retail, education, and manufacturing, highlighting risks in OAuth-connected applications and third-party integrations.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Defending SaaS-based applications against ShinyHunters OAuth abuse
Pattern Type
STIX
Confidence
75%
Valid From
Jul 14, 2026 10:00
Total Sightings
0
Added
Jul 14, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 212.86.125.24

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.