{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "ShinyHunters has historically stolen hundreds of millions of records from cloud-first companies. A negative result confirms that large-scale S3 and repository data theft is not actively occurring in the monitored environment."
      },
      "name": "ShinyHunters Cloud Exfiltration and Ransomware",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1041",
        "attack.t1486",
        "attack.t1555",
        "attack.t1190",
        "collection",
        "credential access",
        "impact",
        "initial access",
        "aws",
        "github"
      ],
      "series": {
        "slug": "gotta-breach-em-all-the-journey-of-shinyhunters",
        "index": 2,
        "title": "Gotta Breach 'Em All! The Journey Of ShinyHunters",
        "total": 2
      },
      "related": [
        {
          "hunt": "cloud-misconfiguration-access",
          "reason": "This hunt focuses on the exfiltration behavior rather than the specific misconfiguration (like public S3 buckets) that allowed it.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        },
        "identity": {
          "name": "Identity / sign-in telemetry",
          "category": "identity",
          "telemetry": [
            "identity"
          ]
        }
      },
      "analysis": "A simple alert for S3 'GetObject' would produce thousands of false positives. This hunt uses a 'funnel' flow to baseline high-volume data access and correlates it with endpoint ransomware behavior, providing the context necessary to identify a data extortion campaign.",
      "coverage": [
        {
          "stage": "collection-and-bulk-data-exfiltration",
          "steps": [
            "bulk-s3-access-lead",
            "github-repo-exfiltration"
          ],
          "status": "covered"
        },
        {
          "stage": "impact-extortion-and-data-leakage",
          "steps": [
            "endpoint-file-encryption"
          ],
          "status": "covered"
        },
        {
          "stage": "initial-access-phishing-and-harvesting",
          "reason": "Belongs to another part of the \"Gotta Breach 'Em All! The Journey Of ShinyHunters\" series.",
          "status": "out_of_scope"
        },
        {
          "stage": "token-theft-and-misconfiguration-access",
          "reason": "Belongs to another part of the \"Gotta Breach 'Em All! The Journey Of ShinyHunters\" series.",
          "status": "out_of_scope"
        },
        {
          "stage": "credential-abuse-and-account-takeover",
          "reason": "Belongs to another part of the \"Gotta Breach 'Em All! The Journey Of ShinyHunters\" series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Phishing and credential harvesting",
            "slug": "initial-access-phishing-and-harvesting",
            "tactic": "initial-access",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "Fake login pages targeting corporate users",
              "Credential harvesting phishing emails",
              "Use of domains: secure.com, chronicle.com, promo.com"
            ]
          },
          {
            "name": "OAuth token theft and cloud misconfigurations",
            "slug": "token-theft-and-misconfiguration-access",
            "tactic": "initial-access",
            "techniques": [
              "T1555",
              "T1190"
            ],
            "observables": [
              "Exposed GitHub OAuth tokens",
              "Compromised Slack tokens",
              "Unsecured AWS S3 buckets",
              "Supply-chain compromise of third-party vendors (Waydev)"
            ]
          },
          {
            "name": "Cloud and SaaS account takeover",
            "slug": "credential-abuse-and-account-takeover",
            "tactic": "credential-access",
            "techniques": [
              "T1555"
            ],
            "observables": [
              "Access to cloud infrastructure lacking MFA",
              "Use of infostealer-harvested credentials",
              "Abuse of valid GitHub and Slack credentials"
            ]
          },
          {
            "name": "Bulk cloud data collection and exfiltration",
            "slug": "collection-and-bulk-data-exfiltration",
            "tactic": "collection",
            "techniques": [
              "T1041"
            ],
            "observables": [
              "Cloning of private GitHub repositories",
              "Bulk S3 bucket object retrieval",
              "Theft of user databases (Tokopedia, Wattpad, Nitro PDF)",
              "Database dumps (SQL, JSON records)"
            ]
          },
          {
            "name": "Data encryption and public extortion",
            "slug": "impact-extortion-and-data-leakage",
            "tactic": "impact",
            "techniques": [
              "T1486"
            ],
            "observables": [
              "Ransomware encryption (reported by Beazley)",
              "Extortion demands for non-disclosure",
              "Public data dumps on RaidForums and darkweb markets"
            ]
          }
        ],
        "summary": "ShinyHunters is a persistent, financially motivated threat brand that evolved from traditional phishing to advanced OAuth token theft and SaaS supply-chain compromises. They pivot from harvested credentials and misconfigured cloud buckets to exfiltrate bulk datasets from providers like AWS, GitHub, and Slack for extortion or public sale on cybercrime forums."
      },
      "severity": "high",
      "rationale": "Focus on AWS accounts containing high-value user databases or PII. Review the last 14 days of CloudTrail Data Events if available, as management events may not show object-level reads.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary is using compromised credentials or OAuth tokens to exfiltrate bulk S3 data and GitHub repositories before deploying ransomware for extortion.",
      "parameters": {
        "scope_hosts": {
          "from": {
            "ref": "Analyst scoping",
            "kind": "manual",
            "observed": "2026-09-24"
          },
          "type": "list[host]",
          "default": [],
          "description": "Optional list of hostnames to focus the endpoint investigation."
        },
        "lookback_days": {
          "from": {
            "ref": "Standard hunt window",
            "kind": "manual",
            "observed": "2026-09-24"
          },
          "type": "number",
          "default": "14",
          "description": "Days of cloud and endpoint history to examine."
        },
        "high_volume_threshold": {
          "from": {
            "ref": "Baseline heuristic",
            "kind": "manual",
            "observed": "2026-09-24"
          },
          "type": "number",
          "default": "100",
          "description": "Minimum count of S3 GetObject calls to consider as bulk access."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.sekoia.com/blog/gotta-breach-em-all-the-journey-of-shinyhunters",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.sekoia.com/blog/gotta-breach-em-all-the-journey-of-shinyhunters",
          "name": "Sekoia \u2014 Gotta Breach 'Em All! The Journey Of ShinyHunters"
        }
      ],
      "blind_spots": [
        {
          "id": "missing-s3-data-logs",
          "risk": "Without data events, we only see management activity (ListBucket) rather than the retrieval of individual records.",
          "stage": "collection-and-bulk-data-exfiltration",
          "question": "Which specific objects within an S3 bucket were retrieved?",
          "requires": "AWS CloudTrail Data Events"
        },
        {
          "id": "github-app-visibility",
          "risk": "Standard logs may show file interactions but not the specific git-cloning action by an OAuth app.",
          "stage": "collection-and-bulk-data-exfiltration",
          "question": "Was a repository cloned using a stolen OAuth token?",
          "requires": "GitHub Enterprise audit logs for individual git-clone commands"
        }
      ]
    },
    "name": "ShinyHunters Cloud Exfiltration and Ransomware",
    "description": "ShinyHunters specializes in cloud-native data theft, often targeting AWS S3 buckets and GitHub repositories for bulk collection. This hunt identifies unusual access patterns in cloud API logs, correlates them with repository cloning activity, and monitors endpoints for the high-volume file renames typical of extortion-driven ransomware. By analyzing the flow from cloud collection to endpoint impact, we can distinguish legitimate data management from a multi-stage extortion campaign."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "gotta-breach-em-all-the-journey-of-shinyhunters",
          "index": 2,
          "title": "Gotta Breach 'Em All! The Journey Of ShinyHunters",
          "total": 2
        },
        "coverage": [
          {
            "stage": "collection-and-bulk-data-exfiltration",
            "steps": [
              "bulk-s3-access-lead",
              "github-repo-exfiltration"
            ],
            "status": "covered"
          },
          {
            "stage": "impact-extortion-and-data-leakage",
            "steps": [
              "endpoint-file-encryption"
            ],
            "status": "covered"
          },
          {
            "stage": "initial-access-phishing-and-harvesting",
            "reason": "Belongs to another part of the \"Gotta Breach 'Em All! The Journey Of ShinyHunters\" series.",
            "status": "out_of_scope"
          },
          {
            "stage": "token-theft-and-misconfiguration-access",
            "reason": "Belongs to another part of the \"Gotta Breach 'Em All! The Journey Of ShinyHunters\" series.",
            "status": "out_of_scope"
          },
          {
            "stage": "credential-abuse-and-account-takeover",
            "reason": "Belongs to another part of the \"Gotta Breach 'Em All! The Journey Of ShinyHunters\" series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An adversary is using compromised credentials or OAuth tokens to exfiltrate bulk S3 data and GitHub repositories before deploying ransomware for extortion.",
        "blind_spots": [
          {
            "id": "missing-s3-data-logs",
            "risk": "Without data events, we only see management activity (ListBucket) rather than the retrieval of individual records.",
            "stage": "collection-and-bulk-data-exfiltration",
            "question": "Which specific objects within an S3 bucket were retrieved?",
            "requires": "AWS CloudTrail Data Events"
          },
          {
            "id": "github-app-visibility",
            "risk": "Standard logs may show file interactions but not the specific git-cloning action by an OAuth app.",
            "stage": "collection-and-bulk-data-exfiltration",
            "question": "Was a repository cloned using a stolen OAuth token?",
            "requires": "GitHub Enterprise audit logs for individual git-clone commands"
          }
        ],
        "scoping_notes": "Focus on AWS accounts containing high-value user databases or PII. Review the last 14 days of CloudTrail Data Events if available, as management events may not show object-level reads.",
        "beyond_detection": "A simple alert for S3 'GetObject' would produce thousands of false positives. This hunt uses a 'funnel' flow to baseline high-volume data access and correlates it with endpoint ransomware behavior, providing the context necessary to identify a data extortion campaign."
      }
    },
    {
      "id": "bulk-s3-access-lead",
      "type": "query",
      "label": "Bulk S3 data retrieval",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT actor_user_name, resource_name, COUNT(*) AS call_count, MIN(time) AS first_seen, MAX(time) AS last_seen, src_endpoint_ip FROM hb_cloud_api_activity WHERE api_service_name = 's3.amazonaws.com' AND api_operation = 'GetObject' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, resource_name, src_endpoint_ip HAVING call_count > {{high_volume_threshold}} ORDER BY call_count DESC",
        "product": "aws",
        "surface": "hb_cloud_api_activity",
        "extension": "aws",
        "description": "Identify cloud identities performing an unusually high volume of S3 GetObject calls, suggesting bulk exfiltration.",
        "expected_signal": "Multiple rows for a single user name accessing thousands of objects in a specific bucket. Rare source IPs for these operations increase suspicion."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Bulk S3 data retrieval",
        "reads": [
          "actor_user_name",
          "api_operation",
          "api_service_name",
          "resource_name",
          "src_endpoint_ip",
          "time"
        ],
        "source": "hb_cloud_api_activity",
        "target": "endpoint",
        "content": "SELECT actor_user_name, resource_name, COUNT(*) AS call_count, MIN(time) AS first_seen, MAX(time) AS last_seen, src_endpoint_ip FROM hb_cloud_api_activity WHERE api_service_name = 's3.amazonaws.com' AND api_operation = 'GetObject' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, resource_name, src_endpoint_ip HAVING call_count > {{high_volume_threshold}} ORDER BY call_count DESC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Multiple rows for a single user name accessing thousands of objects in a specific bucket. Rare source IPs for these operations increase suspicion.",
        "verified": "dry-run",
        "prevalence": {
          "by": "resource_name",
          "key": [
            "actor_user_name"
          ],
          "rare_below": 2
        },
        "verified_at": "2026-10-02",
        "target_extension": "aws"
      }
    },
    {
      "id": "github-repo-exfiltration",
      "type": "query",
      "label": "GitHub repository bulk access",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT actor_user_name, file_path, COUNT(*) AS event_count, MIN(time) AS first_seen FROM hb_file_activity WHERE provider = 'github' AND file_type = 'repo-blob' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, file_path HAVING event_count > 20 ORDER BY event_count DESC",
        "product": "github",
        "surface": "hb_file_activity",
        "extension": "github",
        "description": "Detect bulk reading or cloning of private repositories, a known ShinyHunters tactic.",
        "expected_signal": "A single user name interacting with numerous repo-blobs in a short window. Legitimate CI/CD tools may show high volume, but individual users should not."
      },
      "parents": [
        {
          "id": "bulk-s3-access-lead"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "GitHub repository bulk access",
        "reads": [
          "actor_user_name",
          "file_path",
          "file_type",
          "provider",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT actor_user_name, file_path, COUNT(*) AS event_count, MIN(time) AS first_seen FROM hb_file_activity WHERE provider = 'github' AND file_type = 'repo-blob' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, file_path HAVING event_count > 20 ORDER BY event_count DESC",
        "silence": "not_evidence_of_absence",
        "expected": "A single user name interacting with numerous repo-blobs in a short window. Legitimate CI/CD tools may show high volume, but individual users should not.",
        "verified": "dry-run",
        "verified_at": "2026-10-02",
        "target_extension": "github"
      }
    },
    {
      "id": "endpoint-file-encryption",
      "type": "query",
      "label": "High-volume file rename events",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, COUNT(*) AS rename_count, MIN(time) AS start_time, MAX(time) AS end_time, src_endpoint_ip FROM hb_file_activity WHERE activity_id = 5 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name HAVING rename_count > 500 ORDER BY rename_count DESC",
        "surface": "hb_file_activity",
        "description": "Identify processes that rename files at high frequency, which aligns with recent ShinyHunters extortion tactics.",
        "expected_signal": "A host showing hundreds or thousands of file renames within a few minutes. Normal user activity rarely generates such a high volume of rename events."
      },
      "parents": [
        {
          "id": "bulk-s3-access-lead"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "High-volume file rename events",
        "reads": [
          "activity_id",
          "device_hostname",
          "process_name",
          "src_endpoint_ip",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, COUNT(*) AS rename_count, MIN(time) AS start_time, MAX(time) AS end_time, src_endpoint_ip FROM hb_file_activity WHERE activity_id = 5 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name HAVING rename_count > 500 ORDER BY rename_count DESC",
        "silence": "not_evidence_of_absence",
        "expected": "A host showing hundreds or thousands of file renames within a few minutes. Normal user activity rarely generates such a high volume of rename events.",
        "verified": "dry-run",
        "verified_at": "2026-10-02"
      }
    },
    {
      "id": "triage-shinyhunters-activity",
      "type": "analytic",
      "label": "Triage extortion indicators",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "bulk-s3-access-lead",
          "github-repo-exfiltration",
          "endpoint-file-encryption"
        ],
        "objective": "Determine if the bulk S3 access, GitHub interactions, and endpoint file renames constitute a malicious extortion attempt; perform cross-surface correlation on src_endpoint_ip to link cloud exfiltration leads with endpoint activity.",
        "description": "Combine cloud exfiltration leads with endpoint impact to determine if an active extortion campaign is underway.",
        "max_iterations": 4,
        "expected_signal": "A synthesized verdict linking specific cloud users to endpoint impact.",
        "success_criteria": "A per-host and per-user verdict of malicious, suspicious, or benign, citing specific volumes and timestamps."
      },
      "parents": [
        {
          "id": "github-repo-exfiltration",
          "kind": "merge"
        },
        {
          "id": "endpoint-file-encryption",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route on extortion verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage verdict is malicious for at least one cloud identity or host",
        "condition": "the triage verdict is malicious for at least one cloud identity or host",
        "blind_spot": "missing-s3-data-logs",
        "confidence": "high",
        "description": "Direct the workflow based on the agent's confidence in the extortion threat.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-shinyhunters-activity"
        }
      ]
    },
    {
      "id": "revoke-and-isolate",
      "type": "action",
      "label": "Revoke credentials and isolate hosts",
      "config": {
        "target": "identity",
        "description": "Disable the compromised identity and isolate the affected host to immediately halt exfiltration and further encryption.",
        "instructions": "Revoke the access keys or OAuth tokens for the suspicious cloud identity; isolate the affected host from the network to prevent further encryption.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Comprehensive incident review",
      "config": {
        "assignee": "analyst",
        "description": "Validate the automated findings and assess the extent of data exfiltration.",
        "instructions": "Audit the CloudTrail data events to list every specific S3 object accessed by the actor; review GitHub repository logs for cloning activity; confirm the integrity of backups for encrypted hosts."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "revoke-and-isolate"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Hunt close-out",
      "config": {
        "assignee": "analyst",
        "description": "Record a negative result and update parameters for future runs.",
        "instructions": "Note the absence of bulk exfiltration and ransomware indicators; update parameters if any noise was identified."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        }
      ]
    }
  ]
}