← All hunts high TLP:CLEAR Part 2 of 2

ShinyHunters Cloud Exfiltration and Ransomware

An adversary is using compromised credentials or OAuth tokens to exfiltrate bulk S3 data and GitHub repositories before deploying ransomware for extortion.

Based on research by Sekoia 2026-10-02 9 steps · 3 queries T1041 T1190 T1486 T1555

Brief

Why now

ShinyHunters remains a persistent threat to cloud-first organizations, often stealing hundreds of millions of records for extortion. A recent report by Sekoia, Gotta Breach 'Em All! The Journey Of ShinyHunters, details their evolution from simple data theft to more aggressive extortion tactics. This hunt focuses on the overlap between their cloud-native collection and the endpoint impact that follows.

How the hunt flows

The hunt begins in the cloud. The first query searches AWS CloudTrail logs for unusual patterns of data retrieval. It isolates cloud identities performing a high volume of GetObject calls. The query groups this activity by user and source IP to highlight anomalous bulk access that exceeds standard administrative baselines. High-volume access from a rare IP address provides the first lead.

Once a suspicious identity emerges, the hunt pivots to GitHub audit logs. The adversary often clones private repositories to identify secrets or intellectual property. The query looks for users interacting with an unusual number of repository blobs or performing bulk clones. This step helps confirm the breadth of the exfiltration attempt and identifies which identities are compromised.

In the final technical phase, the hunt moves to the endpoint. ShinyHunters has recently adopted ransomware-like behavior to finalize their extortion. The query scans endpoint file activity for high-frequency rename events. It filters for processes that modify hundreds of files in a short window, which is a common indicator of encryption. By correlating these endpoint renames with the initial cloud exfiltration leads, an analyst can link the entire campaign together.

Finally, a triage step synthesizes these findings. An analyst or agent reviews the timestamps and source IPs across the cloud and endpoint surfaces. This cross-surface correlation is necessary because individual S3 or GitHub alerts are often too noisy to stand alone. Linking bulk theft to local encryption provides the context required for a high-confidence verdict.

What the hunt cannot see

Visibility depends heavily on log configuration. If AWS CloudTrail Data Events are not enabled, the hunt only sees management activity like ListBucket rather than the specific S3 objects retrieved. Similarly, standard GitHub logs may not capture the specific git-clone command if it occurs via certain OAuth application flows. Without these granular logs, an analyst can see that an identity was active but cannot confirm exactly what data was stolen.

Steps

  1. Bulk S3 data retrieval

    Query · baseline

    Identify cloud identities performing an unusually high volume of S3 GetObject calls, suggesting bulk exfiltration.

    reads hb_cloud_api_activitysql
    SELECT actor_user_name, resource_name, COUNT(*) AS call_count, MIN(time) AS first_seen, MAX(time) AS last_seen, src_endpoint_ip FROM hb_cloud_api_activity WHERE api_service_name = 's3.amazonaws.com' AND api_operation = 'GetObject' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, resource_name, src_endpoint_ip HAVING call_count > {{high_volume_threshold}} ORDER BY call_count DESC

    What a hit looks like. Multiple rows for a single user name accessing thousands of objects in a specific bucket. Rare source IPs for these operations increase suspicion.

  2. GitHub repository bulk access

    Query · enrichment

    Detect bulk reading or cloning of private repositories, a known ShinyHunters tactic.

    reads hb_file_activitysql
    SELECT actor_user_name, file_path, COUNT(*) AS event_count, MIN(time) AS first_seen FROM hb_file_activity WHERE provider = 'github' AND file_type = 'repo-blob' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, file_path HAVING event_count > 20 ORDER BY event_count DESC

    What a hit looks like. A single user name interacting with numerous repo-blobs in a short window. Legitimate CI/CD tools may show high volume, but individual users should not.

  3. High-volume file rename events

    Query · detection candidate

    Identify processes that rename files at high frequency, which aligns with recent ShinyHunters extortion tactics.

    reads hb_file_activitysql
    SELECT device_hostname, process_name, COUNT(*) AS rename_count, MIN(time) AS start_time, MAX(time) AS end_time, src_endpoint_ip FROM hb_file_activity WHERE activity_id = 5 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name HAVING rename_count > 500 ORDER BY rename_count DESC

    What a hit looks like. A host showing hundreds or thousands of file renames within a few minutes. Normal user activity rarely generates such a high volume of rename events.

  4. Triage extortion indicators

    Agent triage

    Combine cloud exfiltration leads with endpoint impact to determine if an active extortion campaign is underway.

  5. Route on extortion verdict

    Decision

    Direct the workflow based on the agent's confidence in the extortion threat.

  6. Revoke credentials and isolate hosts

    Response action

    Disable the compromised identity and isolate the affected host to immediately halt exfiltration and further encryption.

  7. Comprehensive incident review

    Analyst task

    Validate the automated findings and assess the extent of data exfiltration.

  8. Hunt close-out

    Analyst task

    Record a negative result and update parameters for future runs.

Coverage

Scenario coverage

StageCoveredHow, or why not
Bulk cloud data collection and exfiltration
T1041
Yes bulk-s3-access-lead, github-repo-exfiltration
Data encryption and public extortion
T1486
Yes endpoint-file-encryption
Phishing and credential harvesting
T1566
Out of scope Belongs to another part of the "Gotta Breach 'Em All! The Journey Of ShinyHunters" series.
OAuth token theft and cloud misconfigurations
T1555 · T1190
Out of scope Belongs to another part of the "Gotta Breach 'Em All! The Journey Of ShinyHunters" series.
Cloud and SaaS account takeover
T1555
Out of scope Belongs to another part of the "Gotta Breach 'Em All! The Journey Of ShinyHunters" series.

Blind spots

  • Needs AWS CloudTrail Data Events. Without data events, we only see management activity (ListBucket) rather than the retrieval of individual records. It would answer Which specific objects within an S3 bucket were retrieved?.
  • Needs GitHub Enterprise audit logs for individual git-clone commands. Standard logs may show file interactions but not the specific git-cloning action by an OAuth app. It would answer Was a repository cloned using a stolen OAuth token?.

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
high_volume_thresholdnumber100Minimum count of S3 GetObject calls to consider as bulk access.
lookback_daysnumber14Days of cloud and endpoint history to examine.
scope_hostslist[host]—Optional list of hostnames to focus the endpoint investigation.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint
Identity / sign-in telemetryidentityidentity

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: A simple alert for S3 'GetObject' would produce thousands of false positives.
  This hunt uses a 'funnel' flow to baseline high-volume data access and correlates
  it with endpoint ransomware behavior, providing the context necessary to identify
  a data extortion campaign.
blind_spots:
- id: missing-s3-data-logs
  question: Which specific objects within an S3 bucket were retrieved?
  requires: AWS CloudTrail Data Events
  risk: Without data events, we only see management activity (ListBucket) rather than
    the retrieval of individual records.
  stage: collection-and-bulk-data-exfiltration
- id: github-app-visibility
  question: Was a repository cloned using a stolen OAuth token?
  requires: GitHub Enterprise audit logs for individual git-clone commands
  risk: Standard logs may show file interactions but not the specific git-cloning
    action by an OAuth app.
  stage: collection-and-bulk-data-exfiltration
coverage:
- stage: collection-and-bulk-data-exfiltration
  status: covered
  steps:
  - bulk-s3-access-lead
  - github-repo-exfiltration
- stage: impact-extortion-and-data-leakage
  status: covered
  steps:
  - endpoint-file-encryption
- reason: Belongs to another part of the "Gotta Breach 'Em All! The Journey Of ShinyHunters"
    series.
  stage: initial-access-phishing-and-harvesting
  status: out_of_scope
- reason: Belongs to another part of the "Gotta Breach 'Em All! The Journey Of ShinyHunters"
    series.
  stage: token-theft-and-misconfiguration-access
  status: out_of_scope
- reason: Belongs to another part of the "Gotta Breach 'Em All! The Journey Of ShinyHunters"
    series.
  stage: credential-abuse-and-account-takeover
  status: out_of_scope
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: promote-to-detection
  justification: ShinyHunters has historically stolen hundreds of millions of records
    from cloud-first companies. A negative result confirms that large-scale S3 and
    repository data theft is not actively occurring in the monitored environment.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An adversary is using compromised credentials or OAuth tokens to exfiltrate
  bulk S3 data and GitHub repositories before deploying ransomware for extortion.
labels:
- hunt
- attack.t1041
- attack.t1486
- attack.t1555
- attack.t1190
- collection
- credential access
- impact
- initial access
- aws
- github
name: ShinyHunters Cloud Exfiltration and Ransomware
parameters:
  high_volume_threshold:
    default: '100'
    description: Minimum count of S3 GetObject calls to consider as bulk access.
    from:
      kind: manual
      observed: '2026-09-24'
      ref: Baseline heuristic
    type: number
  lookback_days:
    default: '14'
    description: Days of cloud and endpoint history to examine.
    from:
      kind: manual
      observed: '2026-09-24'
      ref: Standard hunt window
    type: number
  scope_hosts:
    default: []
    description: Optional list of hostnames to focus the endpoint investigation.
    from:
      kind: manual
      observed: '2026-09-24'
      ref: Analyst scoping
    type: list[host]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://www.sekoia.com/blog/gotta-breach-em-all-the-journey-of-shinyhunters
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Focus on AWS accounts containing high-value user databases or PII. Review
  the last 14 days of CloudTrail Data Events if available, as management events may
  not show object-level reads.
references:
- name: "Sekoia \u2014 Gotta Breach 'Em All! The Journey Of ShinyHunters"
  url: https://www.sekoia.com/blog/gotta-breach-em-all-the-journey-of-shinyhunters
related:
- hunt: cloud-misconfiguration-access
  reason: This hunt focuses on the exfiltration behavior rather than the specific
    misconfiguration (like public S3 buckets) that allowed it.
  relation: out-of-scope-alternative
scenario:
  stages:
  - name: Phishing and credential harvesting
    observables:
    - Fake login pages targeting corporate users
    - Credential harvesting phishing emails
    - 'Use of domains: secure.com, chronicle.com, promo.com'
    slug: initial-access-phishing-and-harvesting
    tactic: initial-access
    techniques:
    - T1566
  - name: OAuth token theft and cloud misconfigurations
    observables:
    - Exposed GitHub OAuth tokens
    - Compromised Slack tokens
    - Unsecured AWS S3 buckets
    - Supply-chain compromise of third-party vendors (Waydev)
    slug: token-theft-and-misconfiguration-access
    tactic: initial-access
    techniques:
    - T1555
    - T1190
  - name: Cloud and SaaS account takeover
    observables:
    - Access to cloud infrastructure lacking MFA
    - Use of infostealer-harvested credentials
    - Abuse of valid GitHub and Slack credentials
    slug: credential-abuse-and-account-takeover
    tactic: credential-access
    techniques:
    - T1555
  - name: Bulk cloud data collection and exfiltration
    observables:
    - Cloning of private GitHub repositories
    - Bulk S3 bucket object retrieval
    - Theft of user databases (Tokopedia, Wattpad, Nitro PDF)
    - Database dumps (SQL, JSON records)
    slug: collection-and-bulk-data-exfiltration
    tactic: collection
    techniques:
    - T1041
  - name: Data encryption and public extortion
    observables:
    - Ransomware encryption (reported by Beazley)
    - Extortion demands for non-disclosure
    - Public data dumps on RaidForums and darkweb markets
    slug: impact-extortion-and-data-leakage
    tactic: impact
    techniques:
    - T1486
  summary: ShinyHunters is a persistent, financially motivated threat brand that evolved
    from traditional phishing to advanced OAuth token theft and SaaS supply-chain
    compromises. They pivot from harvested credentials and misconfigured cloud buckets
    to exfiltrate bulk datasets from providers like AWS, GitHub, and Slack for extortion
    or public sale on cybercrime forums.
series:
  index: 2
  slug: gotta-breach-em-all-the-journey-of-shinyhunters
  title: Gotta Breach 'Em All! The Journey Of ShinyHunters
  total: 2
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  identity:
    category: identity
    name: Identity / sign-in telemetry
    telemetry:
    - identity
tlp: clear
type: investigation
---


# ShinyHunters Cloud Exfiltration and Ransomware

ShinyHunters specializes in cloud-native data theft, often targeting AWS S3 buckets and GitHub repositories for bulk collection. This hunt identifies unusual access patterns in cloud API logs, correlates them with repository cloning activity, and monitors endpoints for the high-volume file renames typical of extortion-driven ransomware. By analyzing the flow from cloud collection to endpoint impact, we can distinguish legitimate data management from a multi-stage extortion campaign.

## bulk-s3-access-lead
<!-- Bulk S3 data retrieval -->
Identify cloud identities performing an unusually high volume of S3 GetObject calls, suggesting bulk exfiltration.

```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days, high_volume_threshold=high_volume_threshold)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: Multiple rows for a single user name accessing thousands of objects in a
  specific bucket. Rare source IPs for these operations increase suspicion.
prevalence:
  by: resource_name
  key:
  - actor_user_name
  rare_below: 2
reads:
- actor_user_name
- api_operation
- api_service_name
- resource_name
- src_endpoint_ip
- time
silence: not_evidence_of_absence
source: hb_cloud_api_activity
verified: dry-run
verified_at: '2026-10-02'
~~~
SELECT actor_user_name, resource_name, COUNT(*) AS call_count, MIN(time) AS first_seen, MAX(time) AS last_seen, src_endpoint_ip FROM hb_cloud_api_activity WHERE api_service_name = 's3.amazonaws.com' AND api_operation = 'GetObject' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, resource_name, src_endpoint_ip HAVING call_count > {{high_volume_threshold}} ORDER BY call_count DESC
```

## parallel-investigation
<!-- Examine repository and endpoint activity -->
parallel:
- → github-repo-exfiltration
- → endpoint-file-encryption
join: → triage-shinyhunters-activity

## github-repo-exfiltration
<!-- GitHub repository bulk access -->
Detect bulk reading or cloning of private repositories, a known ShinyHunters tactic.

```sqlite target=endpoint role=enrichment params=(lookback_days=lookback_days)
~~~yaml
expected: A single user name interacting with numerous repo-blobs in a short window.
  Legitimate CI/CD tools may show high volume, but individual users should not.
reads:
- actor_user_name
- file_path
- file_type
- provider
- time
silence: not_evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-10-02'
~~~
SELECT actor_user_name, file_path, COUNT(*) AS event_count, MIN(time) AS first_seen FROM hb_file_activity WHERE provider = 'github' AND file_type = 'repo-blob' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, file_path HAVING event_count > 20 ORDER BY event_count DESC
```

## endpoint-file-encryption
<!-- High-volume file rename events -->
Identify processes that rename files at high frequency, which aligns with recent ShinyHunters extortion tactics.

```sqlite target=endpoint role=detection-candidate params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: A host showing hundreds or thousands of file renames within a few minutes.
  Normal user activity rarely generates such a high volume of rename events.
reads:
- activity_id
- device_hostname
- process_name
- src_endpoint_ip
- time
silence: not_evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-10-02'
~~~
SELECT device_hostname, process_name, COUNT(*) AS rename_count, MIN(time) AS start_time, MAX(time) AS end_time, src_endpoint_ip FROM hb_file_activity WHERE activity_id = 5 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name HAVING rename_count > 500 ORDER BY rename_count DESC
```

## triage-shinyhunters-activity
<!-- Triage extortion indicators -->
```agent target=hunter
cite: required
context:
- bulk-s3-access-lead
- github-repo-exfiltration
- endpoint-file-encryption
max_iterations: 4
objective: Determine if the bulk S3 access, GitHub interactions, and endpoint file
  renames constitute a malicious extortion attempt; perform cross-surface correlation
  on src_endpoint_ip to link cloud exfiltration leads with endpoint activity.
success_criteria: A per-host and per-user verdict of malicious, suspicious, or benign,
  citing specific volumes and timestamps.
tools:
- endpoint
```

## route-on-verdict
<!-- Route on extortion verdict -->
if~: "the triage verdict is malicious for at least one cloud identity or host" (confidence: high, judge=hunter)
then: → revoke-and-isolate
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: missing-s3-data-logs)
else: → close-out

## revoke-and-isolate
<!-- Revoke credentials and isolate hosts -->
```action target=identity
~~~yaml
approval: required
~~~
Revoke the access keys or OAuth tokens for the suspicious cloud identity; isolate the affected host from the network to prevent further encryption.
```
→ analyst-review

## analyst-review
<!-- Comprehensive incident review -->
```manual target=analyst
Audit the CloudTrail data events to list every specific S3 object accessed by the actor; review GitHub repository logs for cloning activity; confirm the integrity of backups for encrypted hosts.
```
→ end

## close-out
<!-- Hunt close-out -->
```manual target=analyst
Note the absence of bulk exfiltration and ransomware indicators; update parameters if any noise was identified.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.