Threat Actor Profiles

ShinyHunters

Active

3 briefings · first covered 4/29/2026 · last covered 6/28/2026

Exploitable Vulnerabilities, Prioritized

Sorted by CISA KEV status and EPSS exploit probability, same signals as the dashboard.

CVE-2026-35273OracleCriticalCISA KEV · due 2026-06-15EPSS 92.3%

Indicators of Compromise

Subscribe to unlock this actor's full IOC list

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Attribution & Known Techniques

Matched to shinyhunters in MISP's open threat-intelligence galaxy (ransomware cluster).

No technique-level data in the matched source for this actor.

Coverage Timeline

Not yet tracked for this actor

  • CrowdStrike Falcon / SentinelOne Deep Visibility-specific query syntax — hunting queries above (if any) are Microsoft Defender/Sentinel KQL
  • File transfer and exfiltration services used
  • Hunting queries — no FalconFriday rule matched this actor's known techniques