Weekly Intelligence Summary 31 July 2020

July 31, 2020

After exposing more than 300 million user records in May 2020, the “ShinyHunters” threat group has allegedly returned with a second stage of data leaks. Unlike in the first stage, which saw the group advertising data for sale, this time ShinyHunters has flooded criminal forums with leaked databases for free―including many that were already sold. The recently exposed databases comprise more than 408 million records from 26 companies involved in technology, media, travel, e-commerce, finance, and education. A forum user suggested that ShinyHunters is linked to a “sawfish phishing” campaign, targeting GitHub developers’ credentials. This and other ShinyHunters techniques bear close resemblance to those of “GnosticPlayers”; it is realistically possible that the two threat groups are connected, or that the latter simply inspired the former.

Previous Report
Weekly Intelligence Summary 07 August 2020
Weekly Intelligence Summary 07 August 2020

“Lazarus Group” has reportedly used their newly identified “MATA” malware framework and newly created “VHD”...

Next Report
Weekly Intelligence Summary 24 July 2020
Weekly Intelligence Summary 24 July 2020

On 15 July 2020 threat actors compromised 130 Twitter accounts to promote a cryptocurrency scam, which repo...

Want To Try Our Digital Risk Protection Tool?

Get Started Free