ShinyHunters Evolves TTPs: Vishing and Login Harvesting for SSO/MFA Bypass

ShinyHunters Evolves TTPs (TL-2026-0054), also tracked as ShinyHunters, is a high-severity tracked threat-actor profile scored CVSS 8.1, first published 2026-02-03. It is attributed to ShinyHunters (France) with high confidence, affects Multiple SSO/Identity Providers, maps to 49 MITRE ATT&CK techniques (T1003, T1056, T1056.003), and is covered by 15 detection rules and 38 indicators of compromise.

Key facts for TL-2026-0054

Threat ID
TL-2026-0054
Also known as
ShinyHunters
Severity
HIGH
CVSS
8.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N)
Status
ACTIVE
Category
THREAT_ACTOR
First published
2026-02-03
Last reviewed
2026-02-03
Attribution
ShinyHunters
Attribution confidence
HIGH
Nation-state nexus
France
Motivation
FINANCIAL
Target sectors
Telecommunications, Technology, Financial Services, Hospitality, Gaming, Healthcare, Retail, Manufacturing, MSP/MSSP
Target regions
North America, Europe, Global
Detection rules
15
Indicators of compromise
38

Malware and tooling in ShinyHunters Evolves TTPs

Malware and tooling: AnyDesk, ConnectWise - S0591, EvilGinx, Splashtop, Tactical RMM, TeamViewer

ShinyHunters/Scattered Spider has undergone the most dramatic TTP evolution of any cybercriminal group in the 2022-2026 period, progressing from credential stuffing and database exploitation (2020-2021) to SIM swapping and cryptocurrency theft (2022) to sophisticated vishing-based social engineering targeting IT help desks for SSO/MFA bypass (2023-2026). This threat tracks the TTP EVOLUTION and DEFENSIVE DETECTION of vishing-based attacks: how to detect call center social engineering, SSO token theft/replay, MFA fatigue bombing, SIM swap indicators, and the attacker's shift to targeting human trust rather than technical vulnerabilities. Distinct from TL-0013 (the cloud data theft campaign itself), this threat focuses on the evolving attack methodology and how defenders must adapt detection to counter each generation of ShinyHunters TTPs.

How ShinyHunters Evolves TTPs works

ShinyHunters TTP Evolution: From Script Kiddie to ALPHV Affiliate — Detecting the Vishing Kill Chain

The Evolution Timeline — 5 Generations of TTPs:

Generation 1 (2020-2021): Database Exploitation & Credential Stuffing - ShinyHunters emerged selling stolen databases on RaidForums - Targeted exposed Git repositories, misconfigured cloud storage (S3/Azure Blob) - Automated credential stuffing against web applications using leaked credential combo lists - Monetization: selling databases on darknet forums (Tokopedia 91M, Wattpad 271M, Mashable 5.2M) - Detection: standard perimeter defense, WAF rules, login anomaly detection - No social engineering component — purely technical exploitation

Generation 2 (2022): SIM Swapping & Cryptocurrency Theft - Pivoted to targeting mobile carriers for SIM swaps - Used SIM control to bypass SMS-based MFA on cryptocurrency exchanges - Targeted high-net-worth individuals for cryptocurrency theft - Built relationships with telecom insiders for reliable SIM swaps - Detection: SIM swap alerts from carriers, login from new device after phone number change - First social engineering component — but targeted at carrier employees, not victims directly

Generation 3 (2023): Vishing & IT Help Desk Social Engineering - FUNDAMENTAL SHIFT: attacking the human trust layer instead of technical vulnerabilities - Posed as employees calling IT help desk to reset passwords and MFA - Posed as IT help desk calling employees to harvest credentials - Used stolen personal information (LinkedIn, data broker purchases) for impersonation - Native English speakers — no accent barriers in phone-based social engineering - Targeted: MGM Resorts, Caesars Entertainment, Twilio, Mailchimp, Cloudflare - Monetization: data extortion, ALPHV/BlackCat ransomware affiliate - Detection: EXTREMELY DIFFICULT — phone calls leave no traditional logs

Generation 4 (2024-2025): SSO Federation Hijacking & MFA Device Registration - Added federated identity provider to victim SSO tenant - Activated automatic account linking — all victim accounts accessible via attacker IdP - Registered attacker-controlled devices for MFA (TOTP/push) to maintain persistence - Monitored victim incident response via Slack/Teams/Exchange email rules - Used AiTM (adversary-in-the-middle) phishing for session token theft - Enrolled in victim VPN using stolen credentials + registered MFA device - Detection: SSO configuration changes, new IdP federation, MFA device registration anomalies

Generation 5 (2025-2026): AI-Assisted Vishing & Deep Integration - AI voice cloning for more convincing impersonation (emerging) - Automated reconnaissance using LLMs to profile targets and generate pretexts - Cross-referencing multiple data breaches for comprehensive victim profiles - Targeting cloud infrastructure (vSphere/ESXi) for maximum impact - DragonForce ransomware deployment alongside data extortion - Physical threats against employees who resist social engineering - Detection: AI voice detection (nascent), behavioral analytics for anomalous admin actions

The Vishing Kill Chain — What Defenders Must Detect:

Phase 1 — Reconnaissance: - OSINT gathering: LinkedIn profiles, org charts, internal naming conventions - Data broker purchases: phone numbers, home addresses, personal details - Previous breach data: passwords, security questions, personal identifiers - Internal documentation: help desk procedures, password reset policies, MFA enrollment steps - Detection: Monitoring for unusual data access patterns in OSINT-accessible corporate information

Phase 2 — Social Engineering Execution: - Call to help desk impersonating employee → password reset + MFA enrollment - Call to employee impersonating IT staff → credential harvesting + RMM tool installation - SMS phishing with AiTM login portal → session token capture - MFA fatigue bombing → push notification acceptance - SIM swap via telecom insider → SMS MFA bypass - Detection: Help desk call verification (callback to registered number), anomalous password resets, MFA enrollment from new device

Phase 3 — Initial Access: - Login with reset credentials + attacker-registered MFA - VPN enrollment with stolen session tokens - RMM tool (AnyDesk/TeamViewer/Splashtop) providing direct access - AiTM-captured session token replay - Detection: Login from unusual location/device, VPN connection from unregistered device, RMM tool installation without IT ticket

Phase 4 — Persistence & Escalation: - Register new MFA device for the compromised account - Add federated IdP to SSO tenant for persistent access - Create new admin accounts in Azure AD/Entra ID - Modify mailbox rules to suppress security alerts - Disable/modify EDR via compromised security admin accounts - Detection: MFA device registration, SSO federation changes, new cloud admin accounts, mailbox rule creation, EDR policy changes

Phase 5 — Data Theft & Impact: - Bulk export from SharePoint/OneDrive/code repositories/databases - Data staging in centralized location before exfiltration - Exfiltration to MEGA.NZ or attacker-controlled cloud storage - Ransomware deployment (ALPHV/BlackCat, DragonForce) on ESXi servers - Extortion: pay or data published on leak site - Detection: Unusual data downloads, bulk export events, connections to MEGA.NZ, ESXi encryption events

Why Vishing Defeats Traditional Security:

1. No digital artifact at point of attack — phone calls don't generate SIEM events 2. Exploits organizational trust (help desk MUST help employees) 3. Native English speakers eliminate accent-based suspicion 4. Stolen PII makes impersonation highly convincing 5. MFA fatigue works because users are trained to expect MFA prompts 6. Help desk staff are measured on resolution speed, not security scrutiny 7. Traditional security awareness training focuses on phishing emails, not phone calls

MITRE ATT&CK techniques used in TL-2026-0054

credential-access

T1003 OS Credential Dumping; T1110 Brute Force; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1555 Credentials from Password Stores; T1556.006 Multi-Factor Authentication; T1557 Adversary-in-the-Middle; T1606 Forge Web Credentials; T1621 Multi-Factor Authentication Request Generation

collection

T1056 Input Capture; T1056.003 Web Portal Capture; T1114 Email Collection; T1213 Data from Information Repositories; T1530 Data from Cloud Storage

discovery

T1069 Permission Groups Discovery; T1087 Account Discovery; T1526 Cloud Service Discovery; T1538 Cloud Service Dashboard; T1580 Cloud Infrastructure Discovery

defense-evasion

T1070 Indicator Removal; T1078 Valid Accounts; T1550 Use Alternate Authentication Material; T1564 Hide Artifacts; T1684.001 Impersonation

persistence

T1098 Account Manipulation; T1098.001 Additional Cloud Credentials; T1136 Create Account; T1137 Office Application Startup

initial-access

T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1199 Trusted Relationship; T1566 Phishing; T1566.004 Spearphishing Voice

execution

T1204 User Execution

command-and-control

T1219 Remote Access Tools

defense-impairment

T1484 Domain or Tenant Policy Modification; T1578 Modify Cloud Compute Infrastructure; T1685 Disable or Modify Tools

impact

T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery; T1657 Financial Theft

lateral-movement

T1534 Internal Spearphishing

exfiltration

T1537 Transfer Data to Cloud Account; T1567 Exfiltration Over Web Service

resource-development

T1583 Acquire Infrastructure; T1588 Obtain Capabilities; T1608 Stage Capabilities

reconnaissance

T1598 Phishing for Information

Affected products and versions in ShinyHunters Evolves TTPs

  • Multiple — SSO/Identity Providers
    Vulnerable versions: All - social engineering attack
    Fixed in: N/A - user awareness required

Remediation for ShinyHunters Evolves TTPs

Patches

  • Okta — Enhanced admin session binding and token theft detection (2024)
  • Microsoft Entra ID — Token protection and continuous access evaluation (CAE) for session token theft detection
  • Azure AD — Conditional Access: Require compliant device, require MFA re-registration approval

Immediate actions

  • Implement help desk callback verification: ALL password/MFA reset requests must be verified via callback to the employee's registered phone number — never the number calling in
  • Deploy phishing-resistant MFA (FIDO2/WebAuthn hardware keys) for all admin accounts — eliminates MFA fatigue, SIM swap, and AiTM session theft
  • Enable conditional access policies requiring compliant/managed devices for admin portal access — blocks attacker-controlled devices
  • Monitor and alert on MFA device registration events — any new MFA device enrollment should require manager approval
  • Create inbox rules to prevent auto-deletion of security vendor emails — detect mailbox rule manipulation

Workarounds

  • Separate help desk channels for standard vs privileged account operations — elevated verification for admin accounts
  • Implement canary accounts that trigger alerts when credentials are used — detect help desk social engineering attempts
  • Monitor Slack/Teams for keywords indicating incident response awareness by attacker ('breach', 'incident', 'compromised')
  • Restrict RMM tool installations to IT-approved deployment methods only — block unauthorized AnyDesk/TeamViewer/Splashtop

Longer-term hardening

  • Implement video verification for high-risk help desk operations (password reset, MFA change for admin accounts)
  • Deploy SSO federation monitoring: alert on ANY new identity provider addition or trust relationship change
  • Migrate all users to phishing-resistant MFA (FIDO2) — eliminates the entire social engineering MFA bypass attack surface
  • Implement anomalous login detection with device fingerprinting — detect session token replay from new devices
  • Train help desk staff specifically on vishing techniques: voice impersonation, urgency tactics, insider knowledge display, and proper verification procedures
  • Deploy carrier-level SIM swap protections (SIM lock, porting PIN) for all employees with admin access

Weaknesses (CWE) in ShinyHunters Evolves TTPs

CWE-287, CWE-384

Timeline of ShinyHunters Evolves TTPs

  • ShinyHunters emerges on RaidForums selling stolen databases: Tokopedia (91M users), Wattpad (271M users), Microsoft private GitHub repos. TTP: credential stuffing, exposed Git repos, misconfigured S3 buckets. No social engineering — purely technical exploitation. Generation 1 TTPs.
  • ShinyHunters responsible for 50+ major database breaches. Sells on RaidForums and dedicated Telegram channels. TTPs: automated scanning for exposed databases, Git credential harvesting, cloud storage enumeration. Still Generation 1 — no phone-based social engineering.
  • Pivot to SIM swapping: ShinyHunters/Scattered Spider targets mobile carriers and BPO companies. Uses SIM swap control to bypass SMS-based MFA on cryptocurrency exchanges. Targets high-net-worth individuals. First social engineering component — targeting carrier employees. Generation 2 TTPs.
  • 0ktapus phishing campaign: mass SMS phishing targeting Okta credentials. Over 130 organizations compromised including Twilio, Cloudflare, Mailchimp. AiTM phishing portals capture SSO session tokens. Transition from SIM swap to credential phishing at scale. Bridge between Generation 2 and Generation 3.
  • FUNDAMENTAL TTP SHIFT: ShinyHunters/Scattered Spider begins vishing (voice phishing) attacks on IT help desks. Pose as employees requesting password resets and MFA changes. Native English speakers with extensive OSINT on targets. No digital artifacts at point of attack — phone calls don't generate SIEM events. Generation 3 TTPs.
  • Becomes ALPHV/BlackCat ransomware affiliate — first native English-speaking group accepted by Eastern European RaaS operation. Combines social engineering initial access with ransomware deployment. Dual extortion: data theft + encryption. Targeting shifts to large enterprises.
  • MGM Resorts ($100M impact) and Caesars Entertainment ($15M ransom paid) compromised via vishing. Attack: called IT help desk → social engineered password reset → accessed Okta SSO → lateral movement → ALPHV ransomware on ESXi. Demonstrated devastating effectiveness of vishing against major enterprises.
  • Microsoft publishes comprehensive Octo Tempest analysis: 'one of the most dangerous financial criminal groups.' Documents TTP evolution from SIM swapping to sophisticated social engineering to ALPHV affiliate. Physical threats against employees who resist. SSO federation hijacking for persistence.
  • Generation 4 TTP: SSO federation hijacking. Adds attacker-controlled identity provider to victim's SSO tenant. Activates automatic account linking — persistent access via attacker IdP. Registers MFA devices on compromised accounts. Monitors victim IR via Slack/Teams/Exchange.
  • Adopts DragonForce ransomware alongside ALPHV/BlackCat. Targets VMware ESXi servers for maximum impact. Exfiltrates to MEGA.NZ and attacker-controlled S3 buckets. Uses Teleport.sh and AnyDesk for persistence. Continues vishing as primary initial access vector.
  • CISA/FBI update AA23-320A with new Scattered Spider TTPs: enhanced social engineering including posing as employees to convince help desk to reset passwords and transfer MFA to attacker devices. DragonForce ransomware, RattyRAT, Teleport.sh added to toolset. 6 authoring organizations (FBI, CISA, RCMP, ASD, AFP, CCCS, NCSC-UK).
  • Generation 5 TTP emergence: AI voice cloning for more convincing vishing, LLM-assisted reconnaissance and pretext generation, automated cross-referencing of breach databases for victim profiling. Physical threats escalate. Detection requires behavioral analytics beyond traditional signature-based approaches.
  • Threadlinqs analysis: ShinyHunters' 5-generation TTP evolution represents the cybercriminal industry's most significant adaptation. The shift from technical exploitation to human trust exploitation renders traditional perimeter defense insufficient. Vishing attacks leave no digital artifact at point of execution. Detection must shift to post-compromise behavioral indicators: anomalous MFA registration, SSO federation changes, help desk procedure anomalies, and session token replay patterns. The help desk IS the perimeter.
  • As of 2026-05-29, ShinyHunters/Scattered Lapsus$ Hunters remains highly active, with this exact vishing-for-SSO/MFA-bypass method confirmed in Jan-May 2026 (Krebs/Mandiant January attacks, Dataminr Feb helpdesk-vishing recruitment, the May 7-12 Instructure/Canvas 275M-record extortion). No patch applies (social-engineering, CWE-287/384); the Sept 2025 "retirement" was rejected as a rebrand and 2026 arrests hit only affiliates, so ACTIVE stands.

Sources cited for ShinyHunters Evolves TTPs

Threats related to ShinyHunters Evolves TTPs

Detection coverage for TL-2026-0054

As of 2026-02-03, Threadlinqs Intelligence publishes 15 detection rule(s) for TL-2026-0054 across Splunk SPL, Microsoft KQL and Sigma, covering 38 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats