Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors SHADOW-AETHER-015

Also known as: tracked as, Mustang Panda, sophisticated phishing attacks, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, Threat Intelligence, Balkan Camp

Description

SHADOW-AETHER-015 operates primarily against cloud‑based identity and access management (IAM) services such as Okta and Azure AD/Entra ID. The actor abuses legitimate credentials through tailored phishing lures, decoy documents, vishing, and help‑desk impersonation, then enhances its foothold with MFA fatigue or token theft to bypass multi‑factor authentication. In addition to social engineering, SHADOW-AETHER-015 exploits public‑facing vulnerabilities, notably the Oracle PeopleSoft CVE‑2026‑35273 remote code execution flaw used in a 2026 higher–education campaign that reached over 100 institutions. The group’s toolset includes heavily obfuscated binaries and backdoor infrastructures such as SYLVANITE, which it hands over to Volt Typhoon for follow‑on operations, demonstrating a sophisticated operational chain. The actor blends espionage objectives—credential theft and data exfiltration—with financial motives via ransomware and extortion. Its operations reveal a pattern of targeting sectors that house extensive managed identity environments, thereby maximizing the reach and impact of compromised credential pools.

Goals & Targeting

Targeted Sectors

Government
Financial services
Telecommunications
Defense
Healthcare
Education
Manufacturing
Non profit
Energy
Critical infrastructure
Media
Hospitality
Aviation
Pharmaceutical
Aerospace
Information technology
Transportation
Think tank
Retail
Gaming
Maritime
Mining
Chemical
Legal services
Utilities
Nuclear
Entertainment
Oil gas
Construction

Targeted Countries / Regions

US
CN
RU
UA
IR
AU
GB
VN
JP
IL
SA
PK
TW
AE
IN
SG
BY
BR
CA
KR
DE
TR
MX
ES
PL
AZ
RO
FR
NG
KP
IT
LB
KZ

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 2 days ago

Executive Summary

SHADOW-AETHER-015 is a highly adaptable actor that couples sophisticated social engineering—phishing, vishing and help‑desk impersonation—with exploitation of public-facing vulnerabilities such as Oracle PeopleSoft CVE‑2026‑35273 to gain initial access. The group leverages obfuscated binaries and MFA fatigue token theft to evade detection, exfiltrates data through multi‑pressure extortion campaigns that combine ransomware and cloud disruption, and targets high‑value sectors including higher education, government, healthcare, and critical infrastructure.

Goals & Targeting

SHADOW-AETHER-015’s strategic goals center on harvesting privileged cloud identities to facilitate espionage and monetize stolen data through multi‑pressure extortion activities. By compromising IAM systems it gains broad lateral movement, enabling stealthy access to sensitive information across government, NGO, academic, and commercial environments that rely heavily on Okta or Azure AD for authentication.

Enhanced Description

Key Capabilities

  • Use of heavily obfuscated binaries to evade detection
  • Exploitation of public-facing vulnerabilities (CVE‑2026‑35273 in Oracle PeopleSoft)
  • Targeted multi‑pressure extortion campaign (data exfiltration, ransomware, cloud disruption)
  • Tailored phishing lures and decoy documents for initial access
  • Vishing and help‑desk impersonation to steal credentials
  • MFA fatigue and token theft techniques to bypass authentication controls
  • Identity abuse in cloud IAM systems (Okta, Azure AD/Entra ID)
  • Exploitation of internet‑facing edge devices to establish foothold
  • Transfer of access from SYLVANITE cluster to Volt Typhoon for follow‑on operations

MITRE ATT&CK Tactics

Initial Access
Execution
Defense Evasion
Exfiltration

ATT&CK Techniques

T1027
T1027.016
T1027.017
T1027.018
T1190
T1566.001
T1566.002
T1204

Software / Tooling

SYLVANITE
Volt Typhoon
Industroyer

Campaigns & Victims

SHADOW‑AETHER‑015 has executed at least two notable campaigns. The most recent, May–June 2026’s ‘ShinyHunters’ wave exploited Oracle PeopleSoft CVE‑2026‑35273 against over one hundred higher education institutions, leveraging phishing spear‑links and web shells for persistence. Earlier operations included a Deep Panda/Ananta campaign that targeted governments, NGOs, and commercial sectors via vishing and sophisticated social engineering lures, often passing control to backdoor infrastructures such as SYLVANITE before deploying Volt Typhoon. The actor demonstrates the ability to scale attacks, mix espionage and extortion tactics, and co‑operate with other threat actors’ infrastructure streams—e.g., the use of Industroyer components in Ukraine grid disruptions suggests overlap or shared tooling. Operational tempo is high, with rapid pivoting between initial access vectors, exploitation of zero‑days, and lateral movement across cloud IAM ecosystems.

IOC Patterns

  • CVE identifier
  • Zero‑day vulnerability
  • Domain
  • Email
  • File

Recommended Actions

  • Patch Oracle PeopleSoft promptly to remediate CVE‑2026‑35273.
  • Apply patches for other known vulnerabilities such as CVE‑2014-4114 and any applicable zero‑day mitigations.
  • Implement threat intelligence feeds specific to SHADOW-AETHER-015 IOC (domains, emails, file hashes).
  • Deploy EDR solutions that detect obfuscated binaries and known malware families like Industroyer, Volt Typhoon, and SYLVANITE.
  • Strengthen email security with advanced filtering, user training on spear‑phishing lures, and enforce MFA to resist fatigue attacks.
  • Segment networks around higher education environments and isolate critical edge devices exposed to the Internet.
  • Monitor and protect cloud identity providers (Okta, Azure AD/Entra ID) for anomalous credential usage.
  • Conduct regular penetration testing of public-facing applications to identify vulnerabilities before exploitation.

Suggested Tags

APT
Cybercriminal
High-value data theft
Ransomware
Oracle PeopleSoft Exploit
Higher Education Targeting
Multi-pressure Extortion
CVE-2026-35273
Obfuscation
Mustang Panda
Deep Panda
Zero-day vulnerability

Confidence Assessment

Medium to high confidence exists regarding SHADOW‑AETHER‑015’s focus on IAM credential abuse, phishing social engineering, MFA fatigue tactics, and exploitation of Oracle PeopleSoft CVE‑2026‑35273—based on independent reports from CISA and Mandiant. Attribution links suggesting shared infrastructure with groups such as Sandworm remain speculative; the actor’s exact national or organizational origin is unknown. Gaps persist in detailed chain-of-command for persistence activities and complete visibility into all tools employed beyond those publicly documented.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 18 Filename 1 Email Address 1

References

  1. www.trendmicro.com — Cited by web research for: Mustang Panda
  2. attack.mitre.org — Cited by web research for: Sandworm Team
  3. attack.mitre.org — Cited by web research for: Threat Intelligence
  4. www.trendmicro.com — Cited by web research for: T1190
  5. www.crowdstrike.com — Cited by web research for: Fal.Con
  6. https://www.cisa.gov/news-events/bulletins/sb25-363 — Cited by AI analysis.

Intel Summary

27

Techniques

46

Tools

0

Campaigns

29

IOCs

0

Observed Data

7

Tactics

Tags

Ransomware
Critical Infrastructure
Phishing
Data Exfiltration
APT
Cybercriminal
High-value data theft
Oracle PeopleSoft Exploit
Higher Education Targeting
Multi-pressure Extortion
CVE-2026-35273
Obfuscation
Mustang Panda
Deep Panda
Zero-day vulnerability

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.