Also known as: tracked as, Mustang Panda, sophisticated phishing attacks, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, Threat Intelligence, Balkan Camp
SHADOW-AETHER-015 operates primarily against cloud‑based identity and access management (IAM) services such as Okta and Azure AD/Entra ID. The actor abuses legitimate credentials through tailored phishing lures, decoy documents, vishing, and help‑desk impersonation, then enhances its foothold with MFA fatigue or token theft to bypass multi‑factor authentication. In addition to social engineering, SHADOW-AETHER-015 exploits public‑facing vulnerabilities, notably the Oracle PeopleSoft CVE‑2026‑35273 remote code execution flaw used in a 2026 higher–education campaign that reached over 100 institutions. The group’s toolset includes heavily obfuscated binaries and backdoor infrastructures such as SYLVANITE, which it hands over to Volt Typhoon for follow‑on operations, demonstrating a sophisticated operational chain. The actor blends espionage objectives—credential theft and data exfiltration—with financial motives via ransomware and extortion. Its operations reveal a pattern of targeting sectors that house extensive managed identity environments, thereby maximizing the reach and impact of compromised credential pools.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
SHADOW-AETHER-015 is a highly adaptable actor that couples sophisticated social engineering—phishing, vishing and help‑desk impersonation—with exploitation of public-facing vulnerabilities such as Oracle PeopleSoft CVE‑2026‑35273 to gain initial access. The group leverages obfuscated binaries and MFA fatigue token theft to evade detection, exfiltrates data through multi‑pressure extortion campaigns that combine ransomware and cloud disruption, and targets high‑value sectors including higher education, government, healthcare, and critical infrastructure.
Goals & Targeting
SHADOW-AETHER-015’s strategic goals center on harvesting privileged cloud identities to facilitate espionage and monetize stolen data through multi‑pressure extortion activities. By compromising IAM systems it gains broad lateral movement, enabling stealthy access to sensitive information across government, NGO, academic, and commercial environments that rely heavily on Okta or Azure AD for authentication.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
SHADOW‑AETHER‑015 has executed at least two notable campaigns. The most recent, May–June 2026’s ‘ShinyHunters’ wave exploited Oracle PeopleSoft CVE‑2026‑35273 against over one hundred higher education institutions, leveraging phishing spear‑links and web shells for persistence. Earlier operations included a Deep Panda/Ananta campaign that targeted governments, NGOs, and commercial sectors via vishing and sophisticated social engineering lures, often passing control to backdoor infrastructures such as SYLVANITE before deploying Volt Typhoon. The actor demonstrates the ability to scale attacks, mix espionage and extortion tactics, and co‑operate with other threat actors’ infrastructure streams—e.g., the use of Industroyer components in Ukraine grid disruptions suggests overlap or shared tooling. Operational tempo is high, with rapid pivoting between initial access vectors, exploitation of zero‑days, and lateral movement across cloud IAM ecosystems.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Medium to high confidence exists regarding SHADOW‑AETHER‑015’s focus on IAM credential abuse, phishing social engineering, MFA fatigue tactics, and exploitation of Oracle PeopleSoft CVE‑2026‑35273—based on independent reports from CISA and Mandiant. Attribution links suggesting shared infrastructure with groups such as Sandworm remain speculative; the actor’s exact national or organizational origin is unknown. Gaps persist in detailed chain-of-command for persistence activities and complete visibility into all tools employed beyond those publicly documented.
No campaigns linked yet.
No observed data linked yet.
27
Techniques
46
Tools
0
Campaigns
29
IOCs
0
Observed Data
7
Tactics