Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G1057
MITRE ATT&CK Group

ShinyHunters (G1057)

UNC6240Bling Libra
ShareXLinkedInRedditHN

[ShinyHunters](https://attack.mitre.org/groups/G1057) is a cyber criminal collective that has been active since at least 2019 operating under the ShinyCorp persona. [ShinyHunters](https://attack.mitre.org/groups/G1057) has targeted multiple industries and geographic regions gathering legitimate credentials and personally identifiable information (PII) for resale or extortion of victims. [ShinyHunters](https://attack.mitre.org/groups/G1057) has been associated with the broader collective called The Community, also known as The Com whose members have also included [Scattered Spider](https://attack.mitre.org/groups/G1015) and [LAPSUS$](https://attack.mitre.org/groups/G1004). Public reporting has mentioned a variety of names for operations [ShinyHunters](https://attack.mitre.org/groups/G1057) members have reportedly conducted with members of other groups, including “Scattered Lapsus Hunters,” “Scattered Lapsus Shiny Hunters,” and “SLSH.”(Citation: ElecticIQ Buyukkaya_ShinyHunters_Sept2025)(Citation: SOCRadar_ShinyHunters_Mar2024)(Citation: Unit42KelleyVaya_BlingLibra_Aug2024)(Citation: Intel471_SH_Aug2021)(Citation: FBI_SHLMS_May2026)(Citation: Google_SHOracle_Jun2026)(Citation: Mandiant_SHDataTheft_Jan2026)(Citation: Google Salesforce JUN 2025)

▪Techniques used (46)

T1560.002Archive via LibraryT1550.001Application Access TokenT1573.002Asymmetric CryptographyT1585.002Email AccountsT1082System Information DiscoveryT1105Ingress Tool TransferT1190Exploit Public-Facing ApplicationT1530Data from Cloud StorageT1059.007JavaScriptT1078Valid AccountsT1567Exfiltration Over Web ServiceT1598.003Spearphishing LinkT1203Exploitation for Client ExecutionT1528Steal Application Access TokenT1083File and Directory DiscoveryT1588.002ToolT1213.003Code RepositoriesT1684Social EngineeringT1552.001Credentials In FilesT1078.004Cloud AccountsT1078.002Domain AccountsT1016System Network Configuration DiscoveryT1491.001Internal DefacementT1036.005Match Legitimate Resource Name or LocationT1219Remote Access ToolsT1598Phishing for InformationT1195.001Compromise Software Dependencies and Development ToolsT1657Financial TheftT1580Cloud Infrastructure DiscoveryT1018Remote System DiscoveryT1059.009Cloud APIT1583.004ServerT1072Software Deployment ToolsT1588.007Artificial IntelligenceT1110Brute ForceT1213.006DatabasesT1589.001CredentialsT1593.003Code RepositoriesT1583.001DomainsT1090.003Multi-hop ProxyT1587.004ExploitsT1485Data DestructionT1619Cloud Storage Object DiscoveryT1595.002Vulnerability ScanningT1069.003Cloud GroupsT1210Exploitation of Remote Services

▪Software used (1)

S0183Tortool
G1057on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.