{"id":7447,"date":"2025-10-08T00:54:39","date_gmt":"2025-10-08T00:54:39","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=7447"},"modified":"2025-10-08T00:54:39","modified_gmt":"2025-10-08T00:54:39","slug":"shinyhunters-wage-broad-company-extortion-spree-krebs-on-safety","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=7447","title":{"rendered":"ShinyHunters Wage Broad Company Extortion Spree \u2013 Krebs on Safety"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>A cybercriminal group that used voice phishing assaults to siphon greater than a billion information from <strong>Salesforce<\/strong> prospects earlier this 12 months has launched an internet site that threatens to publish knowledge stolen from dozens of Fortune 500 corporations in the event that they refuse to pay a ransom. The group additionally claimed accountability for a current breach involving <strong>Discord<\/strong> person knowledge, and for stealing terabytes of delicate recordsdata from 1000&#8217;s of shoppers of the enterprise software program maker <strong>Purple Hat<\/strong>.<\/p>\n<div id=\"attachment_72275\" style=\"width: 1285px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" aria-describedby=\"caption-attachment-72275\" decoding=\"async\" class=\"size-full wp-image-72275\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/sf-extortionsite.png\" alt=\"\" width=\"1275\" height=\"879\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/sf-extortionsite.png 1275w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/sf-extortionsite-768x529.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/sf-extortionsite-782x539.png 782w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/sf-extortionsite-100x70.png 100w\" sizes=\"auto, (max-width: 1275px) 100vw, 1275px\"\/><\/p>\n<p id=\"caption-attachment-72275\" class=\"wp-caption-text\">The brand new extortion web site tied to ShinyHunters (UNC6040), which threatens to publish stolen knowledge except Salesforce or particular person sufferer corporations comply with pay a ransom.<\/p>\n<\/div>\n<p>In Might 2025, a prolific and amorphous English-speaking cybercrime group often called <strong>ShinyHunters<\/strong> launched a social engineering marketing campaign that used voice phishing to trick targets into connecting a malicious app to their group\u2019s Salesforce portal.<\/p>\n<p>The primary actual particulars concerning the incident got here in early June, when the <strong>Google Risk Intelligence Group <\/strong>(GTIG)\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/voice-phishing-data-extortion\" target=\"_blank\" rel=\"noopener\">warned<\/a> that ShinyHunters \u2014 tracked by Google as <strong>UNC6040 <\/strong>\u2014\u00a0was extorting victims over their stolen Salesforce knowledge, and that the group was poised to launch an information leak website to publicly disgrace sufferer corporations into paying a ransom to maintain their information personal. A month later, Google acknowledged that one in every of its personal company Salesforce situations was impacted within the voice phishing marketing campaign.<\/p>\n<p>Final week, a brand new sufferer shaming weblog dubbed \u201c<strong>Scattered LAPSUS$ Hunters<\/strong>\u201d started publishing the names of corporations that had buyer Salesforce knowledge stolen on account of the Might voice phishing marketing campaign.<\/p>\n<p>\u201cContact us to barter this ransom or all of your prospects knowledge can be leaked,\u201d the web site acknowledged in a message to Salesforce. \u201cIf we come to a decision all particular person extortions in opposition to your prospects can be withdrawn from. No one else should pay us, when you pay, Salesforce, Inc.\u201d<\/p>\n<p>Beneath that message had been greater than three dozen entries for corporations that allegedly had Salesforce knowledge stolen, together with <strong>Toyota<\/strong>, <strong>FedEx<\/strong>, <strong>Disney\/Hulu<\/strong>, and <strong>UPS<\/strong>. The entries for every firm specified the amount of stolen knowledge out there, in addition to the date that the data was retrieved (the acknowledged breach dates vary between Might and September 2025).<\/p>\n<div id=\"attachment_72312\" style=\"width: 759px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-72312\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-72312\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/mandiant-sf.png\" alt=\"\" width=\"749\" height=\"480\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/mandiant-sf.png 866w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/mandiant-sf-768x492.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/mandiant-sf-782x501.png 782w\" sizes=\"auto, (max-width: 749px) 100vw, 749px\"\/><\/p>\n<p id=\"caption-attachment-72312\" class=\"wp-caption-text\">Picture: Mandiant.<\/p>\n<\/div>\n<p>On October 5, the Scattered LAPSUS$ Hunters sufferer shaming and extortion weblog introduced that the group was liable for a breach in September involving a GitLab server utilized by Purple Hat that contained greater than 28,000 Git code repositories, together with greater than 5,000 Buyer Engagement Stories (CERs).<\/p>\n<p>\u201cAlot of folders have their shopper\u2019s secrets and techniques comparable to artifactory entry tokens, git tokens, azure, docker (redhat docker, azure containers, dockerhub), their shopper\u2019s infrastructure particulars within the CERs just like the audits that had been completed for them, and an entire LOT extra, and many others.,\u201d the hackers claimed.<\/p>\n<p>Their claims got here a number of days after a beforehand unknown hacker group calling itself the <strong>Crimson Collective<\/strong> took credit score for the Purple Hat intrusion on Telegram.<\/p>\n<p>Purple Hat <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.redhat.com\/en\/blog\/security-update-incident-related-red-hat-consulting-gitlab-instance\" target=\"_blank\" rel=\"noopener\">disclosed on October 2<\/a> that attackers had compromised an organization GitLab server, and stated it was within the strategy of notifying affected prospects.<\/p>\n<p>\u201cThe compromised GitLab occasion housed consulting engagement knowledge, which can embrace, for instance, Purple Hat\u2019s mission specs, instance code snippets, inside communications about consulting companies, and restricted types of enterprise contact data,\u201d Purple Hat wrote.<\/p>\n<p>Individually, Discord has began emailing customers affected by one other breach claimed by ShinyHunters. Discord <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/discord.com\/press-releases\/update-on-security-incident-involving-third-party-customer-service\" target=\"_blank\" rel=\"noopener\">stated<\/a> an incident on September 20 at a \u201cthird-party customer support supplier\u201d impacted a \u201crestricted variety of customers\u201d who communicated with Discord buyer assist or Belief &amp; Security groups. The knowledge included Discord usernames, emails, IP handle, the final 4 digits of any saved cost playing cards, and authorities ID photos submitted throughout age verification appeals.<\/p>\n<p>The Scattered Lapsus$ Hunters declare they are going to publish knowledge stolen from Salesforce and its prospects if ransom calls for aren\u2019t paid by October 10. The group additionally claims it should quickly start extorting tons of extra organizations that misplaced knowledge in August after a cybercrime group stole <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2025\/09\/the-ongoing-fallout-from-a-breach-at-ai-chatbot-maker-salesloft\/\" target=\"_blank\" rel=\"noopener\">huge quantities of authentication tokens from <strong>Salesloft<\/strong><\/a>, whose AI chatbot is utilized by many company web sites to transform buyer interplay into Salesforce leads.<\/p>\n<p>In a communication despatched to prospects at the moment, Salesforce emphasised that the theft of any third-party Salesloft knowledge allegedly stolen by ShinyHunters didn&#8217;t originate from a vulnerability inside the core Salesforce platform. The corporate additionally careworn that it has no plans to fulfill any extortion calls for.<\/p>\n<p>\u201cSalesforce won&#8217;t interact, negotiate with, or pay any extortion demand,\u201d the message to prospects learn. \u201cOur focus is, and stays, on defending the environment, conducting thorough forensic evaluation, supporting our prospects, and dealing with legislation enforcement and regulatory authorities.\u201d<\/p>\n<p>The GTIG tracked the group behind the Salesloft knowledge thefts as <strong>UNC6395<\/strong>, and says the group has been noticed harvesting the info for authentication tokens tied to a variety of cloud companies like Snowflake and Amazon\u2019s AWS.<\/p>\n<p>Google catalogs Scattered Lapsus$ Hunters by so many UNC names (throw in <strong>UNC6240<\/strong> for good measure) as a result of it&#8217;s regarded as an amalgamation of three hacking teams \u2014 <strong>Scattered Spider<\/strong>, Lapsus$ and ShinyHunters. The members of those teams hail from most of the identical chat channels on the <strong>Com<\/strong>, a principally English-language cybercriminal group that operates throughout an ocean of Telegram and Discord servers.<\/p>\n<p>The Scattered Lapsus$ Hunters darknet weblog is presently offline. The outage seems to have coincided with the disappearance of the group\u2019s new clearnet weblog \u2014 <strong>breachforums[.]hn<\/strong> \u2014 which vanished after shifting its Area Title Service (DNS) servers from DDoS-Guard to Cloudflare.<\/p>\n<p>However earlier than it died, the web sites disclosed that hackers had been exploiting a vital zero-day vulnerability in <strong>Oracle\u2019s E-Enterprise Suite<\/strong> software program. Oracle has since <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.oracle.com\/security-alerts\/alert-cve-2025-61882.html\" target=\"_blank\" rel=\"noopener\">confirmed<\/a> {that a} safety flaw tracked as <strong>CVE-2025-61882<\/strong> permits attackers to carry out unauthenticated distant code execution, and is urging prospects to use an emergency replace to deal with the weak spot.<\/p>\n<p>Mandiant\u2019s <strong>Charles Carmichael<\/strong> <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.linkedin.com\/posts\/charlescarmakal_oracle-security-alert-advisory-cve-2025-activity-7380595612443893760-JNd_\/\" target=\"_blank\" rel=\"noopener\">shared on LinkedIn<\/a> that CVE-2025-61882 was initially exploited in August 2025 by the Clop ransomware gang to steal knowledge from Oracle E-Enterprise Suite servers. <strong>Bleeping Laptop<\/strong> <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/oracle-patches-ebs-zero-day-exploited-in-clop-data-theft-attacks\/\" target=\"_blank\" rel=\"noopener\">writes<\/a> that information of the Oracle zero-day first surfaced on the Scattered Lapsus$ Hunters weblog, which printed a pair of scripts that had been used to take advantage of weak Oracle E-Enterprise Suite situations.<span id=\"more-72279\"\/><\/p>\n<p>On Monday night, KrebsOnSecurity obtained a malware-laced message from a reader that threatened bodily violence except their unspoken calls for had been met. The missive, titled \u201cShiny hunters,\u201d contained the hashtag $LAPSU$$SCATEREDHUNTER, and urged me to go to a web page on limewire[.]com to view their calls for.<\/p>\n<div id=\"attachment_72306\" style=\"width: 760px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-72306\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-72306\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/sh-malwareemail.png\" alt=\"\" width=\"750\" height=\"251\"\/><\/p>\n<p id=\"caption-attachment-72306\" class=\"wp-caption-text\">A screenshot of the phishing message linking to a malicious trojan disguised as a Home windows screenshot file.<\/p>\n<\/div>\n<p>KrebsOnSecurity didn&#8217;t go to this hyperlink, however as a substitute forwarded it to Mandiant, which confirmed that related menacing missives had been despatched to staff at Mandiant and different safety corporations across the identical time.<\/p>\n<p>The hyperlink within the message fetches a malicious trojan disguised as a Home windows screenshot file (Virustotal\u2019s evaluation on this malware is <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.virustotal.com\/gui\/file\/9abe847b497e68919143d4da1bb34e565a7fa9991f51c8f6bb7e5911cee01a24\" target=\"_blank\" rel=\"noopener\">right here<\/a>). Merely viewing the booby-trapped screenshot picture on a Home windows PC is sufficient to trigger the bundled trojan to launch within the background.<\/p>\n<p>Mandiant\u2019s <strong>Austin Larsen<\/strong> stated the trojan is a commercially out there backdoor often called <strong>ASYNCRAT<\/strong>, which is a .NET-based backdoor that communicates utilizing a customized binary protocol over TCP, and might execute shell instructions and obtain plugins to increase its options.<\/p>\n<div id=\"attachment_72292\" style=\"width: 759px\" class=\"wp-caption aligncenter\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/shmalware-vt.png\" target=\"_blank\" rel=\"noopener\"><img aria-describedby=\"caption-attachment-72292\" decoding=\"async\" loading=\"lazy\" class=\"wp-image-72292\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/shmalware-vt.png\" alt=\"\" width=\"749\" height=\"427\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/shmalware-vt.png 1334w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/shmalware-vt-768x438.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/shmalware-vt-782x446.png 782w\" sizes=\"auto, (max-width: 749px) 100vw, 749px\"\/><\/a><\/p>\n<p id=\"caption-attachment-72292\" class=\"wp-caption-text\">A scan of the malicious screenshot file at Virustotal.com exhibits it&#8217;s detected as unhealthy by practically a dozen safety and antivirus instruments.<\/p>\n<\/div>\n<p>\u201cDownloaded plugins could also be executed immediately in reminiscence or saved within the registry,\u201d Larsen wrote in an evaluation shared by way of e-mail. \u201cCapabilities added by way of plugins embrace screenshot seize, file switch, keylogging, video seize, and cryptocurrency mining. ASYNCRAT additionally helps a plugin that targets credentials saved by Firefox and Chromium-based net browsers.\u201d<\/p>\n<p>Malware-laced focused emails are usually not out of character for sure members of the Scattered Lapsus$ Hunters, who&#8217;ve beforehand harassed and threatened safety researchers and even legislation enforcement officers who&#8217;re investigating and warning concerning the extent of their assaults.<\/p>\n<p>With so many large knowledge breaches and ransom assaults now coming from cybercrime teams working on the Com, legislation enforcement companies on either side of the pond are below growing strain to apprehend the legal hackers concerned. In late September, prosecutors within the U.Ok. charged two alleged Scattered Spider members aged 18 and 19 with <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2025\/09\/feds-tie-scattered-spider-duo-to-115m-in-ransoms\/\" target=\"_blank\" rel=\"noopener\">extorting at the very least $115 million in ransom funds<\/a> from corporations victimized by knowledge theft.<\/p>\n<p>U.S. prosecutors heaped their very own prices on the 19 year-old in that duo \u2014 U.Ok. resident <strong>Thalha Jubair <\/strong>\u2014\u00a0who&#8217;s alleged to have been concerned in knowledge ransom assaults in opposition to <strong>Marks &amp; Spencer<\/strong> and <strong>Harrods<\/strong>, the British foot retailer <strong>Co-op Group<\/strong>, and the 2023 intrusions at <strong>MGM Resorts<\/strong> and <strong>Caesars Leisure<\/strong>. Jubair additionally was allegedly a key member of LAPSUS$, a cybercrime group that broke into dozens of expertise corporations starting in late 2021.<\/p>\n<div id=\"attachment_72294\" style=\"width: 759px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-72294\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-72294\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/beaumont-sh.png\" alt=\"\" width=\"749\" height=\"218\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/beaumont-sh.png 1039w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/beaumont-sh-768x224.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/10\/beaumont-sh-782x228.png 782w\" sizes=\"auto, (max-width: 749px) 100vw, 749px\"\/><\/p>\n<p id=\"caption-attachment-72294\" class=\"wp-caption-text\">A Mastodon submit by Kevin Beaumont, lamenting the prevalence of main corporations paying tens of millions to extortionist teen hackers, refers derisively to Thalha Jubair as part of an APT menace often called \u201cSuperior Persistent Youngsters.\u201d<\/p>\n<\/div>\n<p>In August, convicted Scattered Spider member and 20-year-old Florida man <strong>Noah Michael City<\/strong> was <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2025\/08\/sim-swapper-scattered-spider-hacker-gets-10-years\/\" target=\"_blank\" rel=\"noopener\">sentenced to 10 years in federal jail<\/a> and ordered to pay roughly $13 million in restitution to victims.<\/p>\n<p>In April 2025, a 23-year-old Scottish man regarded as an early Scattered Spider member was <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2025\/04\/alleged-scattered-spider-member-extradited-to-u-s\/\" target=\"_blank\" rel=\"noopener\">extradited from Spain to the U.S.<\/a>, the place he&#8217;s dealing with prices of wire fraud, conspiracy and identification theft. U.S. prosecutors allege\u00a0<strong>Tyler Robert Buchanan<\/strong>\u00a0and co-conspirators hacked into dozens of corporations in america and overseas, and that he personally managed greater than $26 million stolen from victims.<\/p>\n<\/p><\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>A cybercriminal group that used voice phishing assaults to siphon greater than a billion information from Salesforce prospects earlier this 12 months has launched an internet site that threatens to publish knowledge stolen from dozens of Fortune 500 corporations in the event that they refuse to pay a ransom. The group additionally claimed accountability for [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":7449,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[5777,1668,2646,262,211,5450,2940,5776],"class_list":["post-7447","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-broad","tag-corporate","tag-extortion","tag-krebs","tag-security","tag-shinyhunters","tag-spree","tag-wage"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/7447","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=7447"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/7447\/revisions"}],"predecessor-version":[{"id":7448,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/7447\/revisions\/7448"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/7449"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=7447"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=7447"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=7447"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-07 02:20:27 UTC -->