Active ransomware operator
← All groupsshinyhunters
152 victims indexed · first seen 11 months ago · last activity 14 hours ago
At a glance
- Status
- active
- First seen
- 11 months ago
- Last activity
- 14 hours ago
- Onion sites
- 2 known endpoints
- Primary sector
- Consumer Services · 18 hits
About
References
1 linkExternal sources curated by the MISP threat-intel community.
Timeline
4 monthsTop countries
Top sectors
MITRE ATT&CK
46 techniques · 14 tacticsTactics
Techniques
- T1016System Network Configuration Discovery
- T1018Remote System Discovery
- T1036.005Match Legitimate Resource Name or Location
- T1059.007JavaScript
- T1059.009Cloud API
- T1069.003Cloud Groups
- T1072Software Deployment Tools
- T1078Valid Accounts
- T1078.002Domain Accounts
- T1078.004Cloud Accounts
- T1082System Information Discovery
- T1083File and Directory Discovery
- T1090.003Multi-hop Proxy
- T1105Ingress Tool Transfer
- T1110Brute Force
- T1190Exploit Public-Facing Application
- T1195.001Compromise Software Dependencies and Development Tools
- T1203Exploitation for Client Execution
- T1210Exploitation of Remote Services
- T1213.003Code Repositories
- T1213.006Databases
- T1219Remote Access Tools
- T1485Data Destruction
- T1491.001Internal Defacement
- T1528Steal Application Access Token
- T1530Data from Cloud Storage
- T1550.001Application Access Token
- T1552.001Credentials In Files
- T1560.002Archive via Library
- T1567Exfiltration Over Web Service
- T1573.002Asymmetric Cryptography
- T1580Cloud Infrastructure Discovery
- T1583.001Domains
- T1583.004Server
- T1585.002Email Accounts
- T1587.004Exploits
- T1588.002Tool
- T1588.007Artificial Intelligence
- T1589.001Credentials
- T1593.003Code Repositories
- T1595.002Vulnerability Scanning
- T1598Phishing for Information
- T1598.003Spearphishing Link
- T1619Cloud Storage Object Discovery
- T1657Financial Theft
- T1684Social Engineering
Recent victims
Loading…
Onion infrastructure
2 known- http://shnyhntww34phqoa6dcgnvps2yu7dlwzmy5lkvejwjdo6z7bmgshzayd.onion
- http://toolatedhs5dtr2pv6h5kdraneak5gs3sxrecqhoufc5e45edior7mqd.onion
Source
Updated 14 hours agoData on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.
Get alerted the next time shinyhunters posts a victim.
Add shinyhunters to your watchlist — Pro pings you within 5 minutes of any new shinyhunters leak-site post, Telegram callout, or affiliate-rebrand inference.

