Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors shinyhunters

Also known as: UNC6240, Bling Libra

Description

ShinyHunters is a financially motivated data-theft and extortion group active since 2020, responsible for high-profile breaches including Ticketmaster (via Snowflake) and PowerSchool; by 2025 they launched a RaaS offering called "shinysp1d3r," and in August 2025 French authorities arrested four members. Known victims: 102

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Education

Targeted Countries / Regions

United States of America
Australia
United Kingdom of Great Britain and Northern Ireland

AI Analysis

· 1 week ago

Executive Summary

ShinyHunters is a medium-sophistication criminal cyber threat actor primarily motivated by financial gain through ransomware and extortion activities. They are known for targeting educational institutions and other sectors in the United States, Australia, and the United Kingdom since their first appearance in April 2024. The group operates with a focus on data theft and has expanded their operations to include a ransomware-as-a-service (RaaS) offering called 'shinysp1d3r.' ShinyHunters has been linked to numerous high-profile breaches across multiple industries, including education, finance, retail, and healthcare. Their activities demonstrate a clear intent to exploit vulnerabilities for financial profit and organizational gain.

Goals & Targeting

ShinyHunters' strategic objectives are driven by financial gain through ransomware and data extortion. Their targeting profile focuses on industries with large user bases and sensitive data, such as education, retail, finance, and healthcare. The group's preference for English-speaking countries (United States, Australia, United Kingdom) suggests a potential geographic focus tied to their operational base or language capabilities. ShinyHunters' victims include both small businesses and large enterprises, indicating an adaptive approach to campaign targeting. Their operations often involve high-profile campaigns that attract media attention and serve as a deterrence to other threat actors.

Enhanced Description

ShinyHunters is a financially motivated cybercriminal group that emerged in 2024, primarily targeting organizations across the education sector and other industries through data-theft and extortion campaigns. Initially known for their involvement in ticket sales fraud via malicious software such as 'Snowflake,' ShinyHunters has evolved into a prominent player in the ransomware landscape. By late 2025, they launched their RaaS offering, 'shinysp1d3r,' which enables affiliates to carry out ransomware attacks under their banner. This expansion underscores their strategic shift toward broader criminal operations. The group has demonstrated significant capability in compromising large enterprise systems, including educational platforms like Instructure (Canva LMS) and McGraw Hill, as well as financial institutions, retail chains, and government entities. ShinyHunters' activities are notable for their use of double extortion tactics—encrypting data and threatening to leak it if demands are not met. This approach has made them one of the most impactful criminal groups in the cyber threat landscape. The arrest of four members by French authorities in August 2025 indicates law enforcement efforts to disrupt their operations, though ShinyHunters remains active as of July 2026.

Key Capabilities

  • Ransomware implementation and deployment
  • Data exfiltration for extortion purposes
  • Use of ransomware-as-a-service (RaaS) model
  • Advanced phishing techniques with malicious email campaigns
  • Network penetration and exploitation
  • Credential harvesting and lateral movement within compromised networks

MITRE ATT&CK Tactics

Initial Access
Defense Evasion
Data Exfiltration
Impact

ATT&CK Techniques

T1059.003 - Spear-phishing via Email attachments, Malicious links
T1055 - Use of legitimate credentials
T1068.004 - Exfiltration over Encrypted Channels (e.g., HTTPS)
T1566.001 - Data Archiving as a Tool or Script for Data Exfiltration
T1539.002 - Use of Cloud Storage as C2 Infrastructure

Software / Tooling

ShinySp1d3r (Ransomware)
Cobalt Strike (for attack coordination)
Snowflake (earlier ticket sales fraud tool)
Malicious email campaigns with phishing payloads
Custom malware for data exfiltration

Campaigns & Victims

ShinyHunters' campaigns are characterized by their double extortion tactics and the use of high-pressure demands to ensure payment. Their victims include educational institutions, healthcare providers, financial services companies, and retail chains. Notable campaigns have targeted organizations such as Instructure (Canva LMS), McGraw Hill, and multiple schools affected by the 2024 breach. The group's operational tempo is steady but often shifts in response to law enforcement actions or public exposure. ShinyHunters has demonstrated a preference for encrypting data and using fear tactics to maximize their financial gain.

IOC Patterns

  • Spear-phishing emails with malicious attachments or links
  • Use of email domains such as 'tuta.io' or 'proton.me'
  • Encrypted communication channels via HTTP/S or cloud services
  • Exfiltration of sensitive data via compromised web services
  • Ransomware payloads delivered through exploit kits or remote access tools

Recommended Actions

  • Implement advanced email filtering to detect and block phishing campaigns.
  • Monitor for suspicious network traffic, especially encrypted communications.
  • Conduct regular backups and ensure they are stored offline.
  • Educate employees on spotting malicious emails and links.
  • Adopt multi-factor authentication (MFA) for critical systems.
  • Perform regular vulnerability assessments and penetration testing.

Suggested Tags

Ransomware
Extortion
Data Theft
Criminal Group
RaaS
Double Extortion

Confidence Assessment

Confidence in ShinyHunters' threat intelligence is high due to their extensive campaign activity, public reporting, and law enforcement actions. However, gaps exist regarding the group's exact geographic origin and the full extent of their operational infrastructure. Additionally, the evolution of their RaaS offering introduces new potential capabilities that may not yet be fully understood.

ATT&CK Techniques

Discovery
7 techniques
Execution
4 techniques
Impact
3 techniques
Reconnaissance
5 techniques
Resource Development
6 techniques
Stealth
5 techniques

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

IPv4 Address 4 URL 2 Domain 14

References

  1. ElecticIQ Buyukkaya_ShinyHunters_Sept2025 — Büyükkaya, A. (2025, September 22). ShinyHunters Calling: Financially Motivated Data Extortion Group Targeting Enterprise Cloud Applications. Retrieved May 18, 2026.
  2. FBI_SHLMS_May2026 — Federal Bureau of Investigation. (2026, May 15). ShinyHunters: Cyber Criminal Group Attacks Learning Management System. Retrieved July 1, 2026.
  3. Google Salesforce JUN 2025 — Google Threat Intelligence Group. (2025, June 4). The Cost of a Call: From Voice Phishing to Data Extortion. Retrieved October 22, 2025.
  4. Intel471_SH_Aug2021 — Intel 471. (2021, August 23). Here’s how to guard your enterprise against ShinyHunters. Retrieved July 29, 2026.
  5. Unit42KelleyVaya_BlingLibra_Aug2024 — Kelley, M., Vaya, C. (2024, August 23). Bling Libra’s Tactical Evolution: The Threat Actor Group Behind ShinyHunters Ransomware. Retrieved May 18, 2026.
  6. Google_SHOracle_Jun2026 — Mandiant, Google Threat Intelligence Group. (2026, June 11). ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit. Retrieved June 11, 2026.
  7. Mandiant_SHDataTheft_Jan2026 — Mandiant. (2026, January 30). Vishing for Access: Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft. Retrieved June 16, 2026.
  8. SOCRadar_ShinyHunters_Mar2024 — SOCRadar. (2024, March 18). Dark Web Profile: ShinyHunters. Retrieved May 18, 2026.

Intel Summary

46

Techniques

0

Tools

78

Campaigns

29

IOCs

0

Observed Data

12

Tactics

Tags

Ransomware
Extortion
Data Theft
Criminal Group
RaaS
Double Extortion

Details

MITRE ID
G1057
Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Apr 23, 2024
Last Seen
Aug 8, 2026
Added
May 4, 2026
STIX ID
intrusion-set--5e30362d-935b-4b1c-8bf2-96c7b7b7e299
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.