ShinyHunters Evolves TTPs: Vishing and Login Harvesting for SSO/MFA Bypass
ShinyHunters Evolves TTPs (TL-2026-0054), also tracked as ShinyHunters, is a high-severity tracked threat-actor profile scored CVSS 8.1, first published 2026-02-03. It is attributed to ShinyHunters (France) with high confidence, affects Multiple SSO/Identity Providers, maps to 49 MITRE ATT&CK techniques (T1003, T1056, T1056.003), and is covered by 15 detection rules and 38 indicators of compromise.
Key facts for TL-2026-0054
- Threat ID
- TL-2026-0054
- Also known as
- ShinyHunters
- Severity
- HIGH
- CVSS
- 8.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N)
- Status
- ACTIVE
- Category
- THREAT_ACTOR
- First published
- 2026-02-03
- Last reviewed
- 2026-02-03
- Attribution
- ShinyHunters
- Attribution confidence
- HIGH
- Nation-state nexus
- France
- Motivation
- FINANCIAL
- Target sectors
- Telecommunications, Technology, Financial Services, Hospitality, Gaming, Healthcare, Retail, Manufacturing, MSP/MSSP
- Target regions
- North America, Europe, Global
- Detection rules
- 15
- Indicators of compromise
- 38
Malware and tooling in ShinyHunters Evolves TTPs
Malware and tooling: AnyDesk, ConnectWise - S0591, EvilGinx, Splashtop, Tactical RMM, TeamViewer
ShinyHunters/Scattered Spider has undergone the most dramatic TTP evolution of any cybercriminal group in the 2022-2026 period, progressing from credential stuffing and database exploitation (2020-2021) to SIM swapping and cryptocurrency theft (2022) to sophisticated vishing-based social engineering targeting IT help desks for SSO/MFA bypass (2023-2026). This threat tracks the TTP EVOLUTION and DEFENSIVE DETECTION of vishing-based attacks: how to detect call center social engineering, SSO token theft/replay, MFA fatigue bombing, SIM swap indicators, and the attacker's shift to targeting human trust rather than technical vulnerabilities. Distinct from TL-0013 (the cloud data theft campaign itself), this threat focuses on the evolving attack methodology and how defenders must adapt detection to counter each generation of ShinyHunters TTPs.
How ShinyHunters Evolves TTPs works
ShinyHunters TTP Evolution: From Script Kiddie to ALPHV Affiliate — Detecting the Vishing Kill Chain
The Evolution Timeline — 5 Generations of TTPs:
Generation 1 (2020-2021): Database Exploitation & Credential Stuffing - ShinyHunters emerged selling stolen databases on RaidForums - Targeted exposed Git repositories, misconfigured cloud storage (S3/Azure Blob) - Automated credential stuffing against web applications using leaked credential combo lists - Monetization: selling databases on darknet forums (Tokopedia 91M, Wattpad 271M, Mashable 5.2M) - Detection: standard perimeter defense, WAF rules, login anomaly detection - No social engineering component — purely technical exploitation
Generation 2 (2022): SIM Swapping & Cryptocurrency Theft - Pivoted to targeting mobile carriers for SIM swaps - Used SIM control to bypass SMS-based MFA on cryptocurrency exchanges - Targeted high-net-worth individuals for cryptocurrency theft - Built relationships with telecom insiders for reliable SIM swaps - Detection: SIM swap alerts from carriers, login from new device after phone number change - First social engineering component — but targeted at carrier employees, not victims directly
Generation 3 (2023): Vishing & IT Help Desk Social Engineering - FUNDAMENTAL SHIFT: attacking the human trust layer instead of technical vulnerabilities - Posed as employees calling IT help desk to reset passwords and MFA - Posed as IT help desk calling employees to harvest credentials - Used stolen personal information (LinkedIn, data broker purchases) for impersonation - Native English speakers — no accent barriers in phone-based social engineering - Targeted: MGM Resorts, Caesars Entertainment, Twilio, Mailchimp, Cloudflare - Monetization: data extortion, ALPHV/BlackCat ransomware affiliate - Detection: EXTREMELY DIFFICULT — phone calls leave no traditional logs
Generation 4 (2024-2025): SSO Federation Hijacking & MFA Device Registration - Added federated identity provider to victim SSO tenant - Activated automatic account linking — all victim accounts accessible via attacker IdP - Registered attacker-controlled devices for MFA (TOTP/push) to maintain persistence - Monitored victim incident response via Slack/Teams/Exchange email rules - Used AiTM (adversary-in-the-middle) phishing for session token theft - Enrolled in victim VPN using stolen credentials + registered MFA device - Detection: SSO configuration changes, new IdP federation, MFA device registration anomalies
Generation 5 (2025-2026): AI-Assisted Vishing & Deep Integration - AI voice cloning for more convincing impersonation (emerging) - Automated reconnaissance using LLMs to profile targets and generate pretexts - Cross-referencing multiple data breaches for comprehensive victim profiles - Targeting cloud infrastructure (vSphere/ESXi) for maximum impact - DragonForce ransomware deployment alongside data extortion - Physical threats against employees who resist social engineering - Detection: AI voice detection (nascent), behavioral analytics for anomalous admin actions
The Vishing Kill Chain — What Defenders Must Detect:
Phase 1 — Reconnaissance: - OSINT gathering: LinkedIn profiles, org charts, internal naming conventions - Data broker purchases: phone numbers, home addresses, personal details - Previous breach data: passwords, security questions, personal identifiers - Internal documentation: help desk procedures, password reset policies, MFA enrollment steps - Detection: Monitoring for unusual data access patterns in OSINT-accessible corporate information
Phase 2 — Social Engineering Execution: - Call to help desk impersonating employee → password reset + MFA enrollment - Call to employee impersonating IT staff → credential harvesting + RMM tool installation - SMS phishing with AiTM login portal → session token capture - MFA fatigue bombing → push notification acceptance - SIM swap via telecom insider → SMS MFA bypass - Detection: Help desk call verification (callback to registered number), anomalous password resets, MFA enrollment from new device
Phase 3 — Initial Access: - Login with reset credentials + attacker-registered MFA - VPN enrollment with stolen session tokens - RMM tool (AnyDesk/TeamViewer/Splashtop) providing direct access - AiTM-captured session token replay - Detection: Login from unusual location/device, VPN connection from unregistered device, RMM tool installation without IT ticket
Phase 4 — Persistence & Escalation: - Register new MFA device for the compromised account - Add federated IdP to SSO tenant for persistent access - Create new admin accounts in Azure AD/Entra ID - Modify mailbox rules to suppress security alerts - Disable/modify EDR via compromised security admin accounts - Detection: MFA device registration, SSO federation changes, new cloud admin accounts, mailbox rule creation, EDR policy changes
Phase 5 — Data Theft & Impact: - Bulk export from SharePoint/OneDrive/code repositories/databases - Data staging in centralized location before exfiltration - Exfiltration to MEGA.NZ or attacker-controlled cloud storage - Ransomware deployment (ALPHV/BlackCat, DragonForce) on ESXi servers - Extortion: pay or data published on leak site - Detection: Unusual data downloads, bulk export events, connections to MEGA.NZ, ESXi encryption events
Why Vishing Defeats Traditional Security:
1. No digital artifact at point of attack — phone calls don't generate SIEM events 2. Exploits organizational trust (help desk MUST help employees) 3. Native English speakers eliminate accent-based suspicion 4. Stolen PII makes impersonation highly convincing 5. MFA fatigue works because users are trained to expect MFA prompts 6. Help desk staff are measured on resolution speed, not security scrutiny 7. Traditional security awareness training focuses on phishing emails, not phone calls
MITRE ATT&CK techniques used in TL-2026-0054
credential-access
T1003 OS Credential Dumping; T1110 Brute Force; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1555 Credentials from Password Stores; T1556.006 Multi-Factor Authentication; T1557 Adversary-in-the-Middle; T1606 Forge Web Credentials; T1621 Multi-Factor Authentication Request Generation
collection
T1056 Input Capture; T1056.003 Web Portal Capture; T1114 Email Collection; T1213 Data from Information Repositories; T1530 Data from Cloud Storage
discovery
T1069 Permission Groups Discovery; T1087 Account Discovery; T1526 Cloud Service Discovery; T1538 Cloud Service Dashboard; T1580 Cloud Infrastructure Discovery
defense-evasion
T1070 Indicator Removal; T1078 Valid Accounts; T1550 Use Alternate Authentication Material; T1564 Hide Artifacts; T1684.001 Impersonation
persistence
T1098 Account Manipulation; T1098.001 Additional Cloud Credentials; T1136 Create Account; T1137 Office Application Startup
initial-access
T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1199 Trusted Relationship; T1566 Phishing; T1566.004 Spearphishing Voice
execution
command-and-control
defense-impairment
T1484 Domain or Tenant Policy Modification; T1578 Modify Cloud Compute Infrastructure; T1685 Disable or Modify Tools
impact
T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery; T1657 Financial Theft
lateral-movement
exfiltration
T1537 Transfer Data to Cloud Account; T1567 Exfiltration Over Web Service
resource-development
T1583 Acquire Infrastructure; T1588 Obtain Capabilities; T1608 Stage Capabilities
reconnaissance
Affected products and versions in ShinyHunters Evolves TTPs
- Multiple — SSO/Identity Providers
Vulnerable versions: All - social engineering attack
Fixed in: N/A - user awareness required
Remediation for ShinyHunters Evolves TTPs
Patches
- Okta — Enhanced admin session binding and token theft detection (2024)
- Microsoft Entra ID — Token protection and continuous access evaluation (CAE) for session token theft detection
- Azure AD — Conditional Access: Require compliant device, require MFA re-registration approval
Immediate actions
- Implement help desk callback verification: ALL password/MFA reset requests must be verified via callback to the employee's registered phone number — never the number calling in
- Deploy phishing-resistant MFA (FIDO2/WebAuthn hardware keys) for all admin accounts — eliminates MFA fatigue, SIM swap, and AiTM session theft
- Enable conditional access policies requiring compliant/managed devices for admin portal access — blocks attacker-controlled devices
- Monitor and alert on MFA device registration events — any new MFA device enrollment should require manager approval
- Create inbox rules to prevent auto-deletion of security vendor emails — detect mailbox rule manipulation
Workarounds
- Separate help desk channels for standard vs privileged account operations — elevated verification for admin accounts
- Implement canary accounts that trigger alerts when credentials are used — detect help desk social engineering attempts
- Monitor Slack/Teams for keywords indicating incident response awareness by attacker ('breach', 'incident', 'compromised')
- Restrict RMM tool installations to IT-approved deployment methods only — block unauthorized AnyDesk/TeamViewer/Splashtop
Longer-term hardening
- Implement video verification for high-risk help desk operations (password reset, MFA change for admin accounts)
- Deploy SSO federation monitoring: alert on ANY new identity provider addition or trust relationship change
- Migrate all users to phishing-resistant MFA (FIDO2) — eliminates the entire social engineering MFA bypass attack surface
- Implement anomalous login detection with device fingerprinting — detect session token replay from new devices
- Train help desk staff specifically on vishing techniques: voice impersonation, urgency tactics, insider knowledge display, and proper verification procedures
- Deploy carrier-level SIM swap protections (SIM lock, porting PIN) for all employees with admin access
Weaknesses (CWE) in ShinyHunters Evolves TTPs
CWE-287, CWE-384
Timeline of ShinyHunters Evolves TTPs
- ShinyHunters emerges on RaidForums selling stolen databases: Tokopedia (91M users), Wattpad (271M users), Microsoft private GitHub repos. TTP: credential stuffing, exposed Git repos, misconfigured S3 buckets. No social engineering — purely technical exploitation. Generation 1 TTPs.
- ShinyHunters responsible for 50+ major database breaches. Sells on RaidForums and dedicated Telegram channels. TTPs: automated scanning for exposed databases, Git credential harvesting, cloud storage enumeration. Still Generation 1 — no phone-based social engineering.
- Pivot to SIM swapping: ShinyHunters/Scattered Spider targets mobile carriers and BPO companies. Uses SIM swap control to bypass SMS-based MFA on cryptocurrency exchanges. Targets high-net-worth individuals. First social engineering component — targeting carrier employees. Generation 2 TTPs.
- 0ktapus phishing campaign: mass SMS phishing targeting Okta credentials. Over 130 organizations compromised including Twilio, Cloudflare, Mailchimp. AiTM phishing portals capture SSO session tokens. Transition from SIM swap to credential phishing at scale. Bridge between Generation 2 and Generation 3.
- FUNDAMENTAL TTP SHIFT: ShinyHunters/Scattered Spider begins vishing (voice phishing) attacks on IT help desks. Pose as employees requesting password resets and MFA changes. Native English speakers with extensive OSINT on targets. No digital artifacts at point of attack — phone calls don't generate SIEM events. Generation 3 TTPs.
- Becomes ALPHV/BlackCat ransomware affiliate — first native English-speaking group accepted by Eastern European RaaS operation. Combines social engineering initial access with ransomware deployment. Dual extortion: data theft + encryption. Targeting shifts to large enterprises.
- MGM Resorts ($100M impact) and Caesars Entertainment ($15M ransom paid) compromised via vishing. Attack: called IT help desk → social engineered password reset → accessed Okta SSO → lateral movement → ALPHV ransomware on ESXi. Demonstrated devastating effectiveness of vishing against major enterprises.
- Microsoft publishes comprehensive Octo Tempest analysis: 'one of the most dangerous financial criminal groups.' Documents TTP evolution from SIM swapping to sophisticated social engineering to ALPHV affiliate. Physical threats against employees who resist. SSO federation hijacking for persistence.
- Generation 4 TTP: SSO federation hijacking. Adds attacker-controlled identity provider to victim's SSO tenant. Activates automatic account linking — persistent access via attacker IdP. Registers MFA devices on compromised accounts. Monitors victim IR via Slack/Teams/Exchange.
- Adopts DragonForce ransomware alongside ALPHV/BlackCat. Targets VMware ESXi servers for maximum impact. Exfiltrates to MEGA.NZ and attacker-controlled S3 buckets. Uses Teleport.sh and AnyDesk for persistence. Continues vishing as primary initial access vector.
- CISA/FBI update AA23-320A with new Scattered Spider TTPs: enhanced social engineering including posing as employees to convince help desk to reset passwords and transfer MFA to attacker devices. DragonForce ransomware, RattyRAT, Teleport.sh added to toolset. 6 authoring organizations (FBI, CISA, RCMP, ASD, AFP, CCCS, NCSC-UK).
- Generation 5 TTP emergence: AI voice cloning for more convincing vishing, LLM-assisted reconnaissance and pretext generation, automated cross-referencing of breach databases for victim profiling. Physical threats escalate. Detection requires behavioral analytics beyond traditional signature-based approaches.
- Threadlinqs analysis: ShinyHunters' 5-generation TTP evolution represents the cybercriminal industry's most significant adaptation. The shift from technical exploitation to human trust exploitation renders traditional perimeter defense insufficient. Vishing attacks leave no digital artifact at point of execution. Detection must shift to post-compromise behavioral indicators: anomalous MFA registration, SSO federation changes, help desk procedure anomalies, and session token replay patterns. The help desk IS the perimeter.
- As of 2026-05-29, ShinyHunters/Scattered Lapsus$ Hunters remains highly active, with this exact vishing-for-SSO/MFA-bypass method confirmed in Jan-May 2026 (Krebs/Mandiant January attacks, Dataminr Feb helpdesk-vishing recruitment, the May 7-12 Instructure/Canvas 275M-record extortion). No patch applies (social-engineering, CWE-287/384); the Sept 2025 "retirement" was rejected as a rebrand and 2026 arrests hit only affiliates, so ACTIVE stands.
Sources cited for ShinyHunters Evolves TTPs
- CISA/FBI — Scattered Spider Joint Advisory AA23-320A (Updated July 2025)
- Microsoft — Octo Tempest Crosses Boundaries: Extortion, Encryption, Destruction
- MITRE ATT&CK — Scattered Spider Group G1015
- CrowdStrike — Scattered Spider Escalates Attacks
- Google Mandiant — Defending vSphere from UNC3944
- Google Mandiant — UNC3944 Proactive Hardening Recommendations
- CrowdStrike — Analysis of Intrusion Campaign Targeting Telecom and BPO Companies
- Check Point — Exposing Scattered Spider: New Indicators for Enterprise and Aviation Threats
Threats related to ShinyHunters Evolves TTPs
- ShinyHunters-Branded Extortion Campaign Expands with Vishing & SSO Attacks
- ShinyHunters Extortion Campaign - Evolved Vishing and SSO Credential Theft
- ShinyHunters SSO Vishing Campaign - Cloud Data Theft via Social Engineering
- Infinite Campus Salesforce Breach by ShinyHunters / UNC6040 — 137,100 K-12 School Staff Accounts Exfiltrated and Extorted
- ShinyHunters Mass Defacement of Canvas LMS — Instructure Re-Breach Extortion Campaign Affecting ~330 Educational Institutions (May 2026)
- Device Code Phishing: OAuth Device Authorization Grant Abuse Bypasses All MFA Forms, Including Passkeys
Detection coverage for TL-2026-0054
As of 2026-02-03, Threadlinqs Intelligence publishes 15 detection rule(s) for TL-2026-0054 across Splunk SPL, Microsoft KQL and Sigma, covering 38 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.