ShinyHunters Group Targets Over 100 Enterprises, Including Canva, Atlassian, and Epic Games
A recent increase in infrastructure deployment reflects the tactics of the SLSH alliance, comprising threat actors Scattered Spider, LAPSUS$, and ShinyHunters. This sophisticated identity-theft campaign targets Single Sign-On (SSO) platforms, notably…
A recent increase in infrastructure deployment reflects the tactics of the SLSH alliance, comprising threat actors Scattered Spider, LAPSUS$, and ShinyHunters. This sophisticated identity-theft campaign targets Single Sign-On (SSO) platforms, notably Okta, across over 100 high-value enterprises. It is a human-led operation utilizing voice phishing ("vishing") to bypass Multi-Factor Authentication (MFA) systems.
Attackers use a "Live Phishing Panel" to intercept credentials and MFA tokens during active login sessions, providing persistent access to corporate environments.
Silent Push has identified a surge in infrastructure deployment matching the TTPs (Tactics, Techniques, and Procedures) of SLSH. This hybrid approach targets enterprise identity providers and involves human interaction, where attackers manipulate live phishing pages while engaging help desks and employees, adapting to specific login prompts.
Emerging from "The Com" ecosystem, SLSH combines Scattered Spider's social engineering with LAPSUS$'s extortion methods. The threat targets sectors including technology, finance, healthcare, real estate, and infrastructure. Organizations detected as targets within the past 30 days include Atlassian, Canva, Epic Games, HubSpot, Zoom, Blackstone, RBC, State Street, Biogen, Moderna, Simon Property Group, Zillow, AECOM, and Halliburton.
This sophisticated identity-theft campaign targets Single Sign-On (SSO) platforms, notably Okta, across over 100 high-value enterprises.
Conventional security awareness training is insufficient against this threat. SLSH combines technical skill and social engineering precision, using a compromised SSO account as a "skeleton key" to enterprise applications.
Following LAPSUS$'s strategy, the group focuses on rapid data exfiltration for extortion. After SSO compromise, attackers use internal communication platforms like Slack and Microsoft Teams to gain higher privileges. They then encrypt critical data and demand ransom, combining theft with operational disruption.
Organizations must implement countermeasures, alerting staff about ongoing activities. Employee awareness is crucial against social manipulation. Forensic audits of Okta and other SSO provider logs should seek "New Device Enrolled" events followed by logins from unfamiliar IP addresses.
Pre-attack intelligence capabilities should be deployed to prevent infrastructure setup. Silent Push's Indicators of Future Attack (IOFA™) feeds operate at the DNS level to block malicious domains before they become operational. Organizations should not wait for breach notifications; prevention opportunities diminish once attacks start targeting specific employees.
Based on reporting by GBHackers.
