{"id":6143,"date":"2025-08-14T10:03:38","date_gmt":"2025-08-14T10:03:38","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/08\/14\/shinyhunters-possibly-collaborates-with-scattered-spider-in-salesforce-attack-campaigns\/"},"modified":"2025-08-14T10:03:38","modified_gmt":"2025-08-14T10:03:38","slug":"shinyhunters-possibly-collaborates-with-scattered-spider-in-salesforce-attack-campaigns","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/08\/14\/shinyhunters-possibly-collaborates-with-scattered-spider-in-salesforce-attack-campaigns\/","title":{"rendered":"ShinyHunters Possibly Collaborates With Scattered Spider in Salesforce Attack Campaigns"},"content":{"rendered":"<p>    ShinyHunters Possibly Collaborates With Scattered Spider in Salesforce Attack Campaigns<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The notorious ShinyHunters cybercriminal group has emerged from a year-long hiatus with a sophisticated new wave of attacks targeting Salesforce platforms across major organizations, including high-profile victims like Google.<\/p>\n<p>This resurgence marks a significant tactical evolution for the financially motivated threat actors, who have traditionally focused on database exploitation and credential theft rather than the complex social engineering schemes now being employed.<\/p>\n<p>What makes this campaign particularly alarming is its striking resemblance to operations typically attributed to the Scattered Spider hacking collective.<\/p>\n<p>The convergence of tactics suggests a potential collaboration between these two formidable threat groups, raising concerns about an escalating landscape of coordinated cybercriminal activity.<\/p>\n<p>The attacks have specifically targeted organizations across retail, aviation, and insurance sectors, with victims spanning luxury brands and technology service providers.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj1xIQ08a_UlCzNigyywCjO3uHauDfzQrCCJ422k96AaqaUfF3LY2t8dmgHcwRQ1K9LgjHWvYfhu5hVBrvTNbKlTKJ-45A4EwLWQBN47TmA_oR0bXBUQXiXxAyuaQGWeQsJmcArA9P_LkGCJS-k16pwgfWEudl-wtuE5JwNqIZf3z1ie-yC1FRAu_Dulz4\/s16000\/ShinyHunters%2520first%2520gained%2520notoriety%2520by%2520advertising%252091%2520million%2520Tokopedia%2520user%2520records%2520for%2520sale%2520on%2520%25E2%2580%259CEmpire%2520Market%25E2%2580%259D%2520in%25202020%2520%28Source%2520-%2520Reliaquest%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">ShinyHunters first gained notoriety by advertising 91 million Tokopedia user records for sale on \u201cEmpire Market\u201d in 2020 (Source \u2013 Reliaquest)<\/figcaption><\/figure>\n<\/div>\n<p>ReliaQuest analysts <a href=\"https:\/\/reliaquest.com\/blog\/threat-spotlight-shinyhunters-data-breach-targets-salesforce-amid-scattered-spider-collaboration\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> compelling evidence supporting this collaboration theory through comprehensive domain analysis and infrastructure investigation.<\/p>\n<p>The research revealed coordinated ticket-themed phishing domains and Salesforce credential harvesting pages, indicating a systematic approach to victim targeting.<\/p>\n<p>Most notably, investigators discovered the emergence of a BreachForums user with the alias \u201cSp1d3rhunters\u201d\u2014a clever combination of both group names\u2014who was linked to previous ShinyHunters breaches and appeared to leak Ticketmaster data in July 2024.<\/p>\n<p>The technical sophistication of these attacks represents a significant departure from ShinyHunters\u2019 historical methods.<\/p>\n<p>The group has adopted <a href=\"https:\/\/cybersecuritynews.com\/scattered-spider-hackers-aviation\/\" target=\"_blank\" rel=\"noreferrer noopener\">Scattered Spider<\/a>\u2018s signature techniques, including highly targeted vishing campaigns where attackers impersonate IT support staff to manipulate victims into authorizing malicious \u201cconnected apps.\u201d<\/p>\n<p>These applications masquerade as legitimate Salesforce tools while enabling large-scale data exfiltration.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-advanced-infrastructure-and-evasion-techniques\"><strong>Advanced Infrastructure and Evasion Techniques<\/strong><\/h2>\n<p>The campaign\u2019s infrastructure reveals meticulous planning and advanced evasion capabilities.<\/p>\n<p>Investigators uncovered multiple malicious domains registered between June 20-30, 2025, following consistent naming patterns such as <code>ticket-lvmh.com<\/code>, <code>ticket-dior.com<\/code>, and <code>ticket-louisvuitton.com<\/code>.<\/p>\n<p>These domains shared common registry characteristics, including registration through GMO Internet using temporary email addresses like <code>email@mailshan.com<\/code> and Cloudflare-masked nameservers for additional <a href=\"https:\/\/cybersecuritynews.com\/malware-obfuscation\/\" target=\"_blank\" rel=\"noreferrer noopener\">obfuscation<\/a>.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhSJeIXKI-v30VGxHynUUL9wMPM2qIq0YXi1dhEpk7Rt6gaMFwWNFJ15jy0SmzOKm2-g60OSD3-ADHmoq78ra8SPapbhkVticnnDn5x9fDhAzfFbSxCrGehGZlEeQNFlFOltOcl_LCvfgA6sABhwkTUlsg16leE3OTezb11touJyULfMsSl8ju-z2LhBo0\/s16000\/Phishing%2520page%2520hosted%2520at%2520dashboard-salesforce%255B.%255Dcom%2520%28Source%2520-%2520Reliaquest%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Okta phishing page hosted at ticket-dior[.]com in June 2025 (Source \u2013 Reliaquest)<\/figcaption><\/figure>\n<\/div>\n<p>The attackers deployed sophisticated phishing kits hosting single sign-on (SSO) login pages, with domains like <code>dashboard-salesforce.com<\/code> actively serving Okta-branded credential harvesting interfaces.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgnr4tWc78P7fkj66V3U-p4K9OutDNQZFRqOGyOTBdEo_9avndEh2zHc3hpdXvjjvJ3mP79ldbxlwEkN3RTet-BT-9ZDOykbW3bzwVt8aFw6aFfmtv2YTaoUJUIjYyyyNVWYxuHItZRvombzVic8Wah14n9SCv06bslJKw-nPqJOa03wioDRGh2AZQVnHQ\/s16000\/Okta%2520phishing%2520page%2520hosted%2520at%2520ticket-dior%255B.%255Dcom%2520in%2520June%25202025%2520%28Source%2520-%2520Reliaquest%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Phishing page hosted at dashboard-salesforce[.]com (Source \u2013 Reliaquest)<\/figcaption><\/figure>\n<\/div>\n<p>The malicious infrastructure leveraged VPN obfuscation through Mullvad VPN services to perform <a href=\"https:\/\/cybersecuritynews.com\/cl0p-ransomware-data-exfiltration-vulnerable\/\" target=\"_blank\" rel=\"noreferrer noopener\">data exfiltration<\/a> from compromised Salesforce instances.<\/p>\n<p>Particularly concerning is the rebranding of legitimate Salesforce \u201cData Loader\u201d applications as \u201cMy Ticket Portal\u201d during vishing campaigns, demonstrating the group\u2019s ability to weaponize familiar business tools against unsuspecting employees.<\/p>\n<p>This tactical evolution, combined with the synchronized targeting patterns observed across both ShinyHunters and Scattered Spider operations, suggests that financial services and technology providers should prepare for intensified attacks in the coming months.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong><code>Boost\u00a0your\u00a0SOC and help your team protect your business with free top-notch threat intelligence:\u00a0<a href=\"https:\/\/intelligence.any.run\/plans\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=alert_fatigue&amp;utm_content=lookup_plan&amp;utm_term=120825\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Request TI Lookup Premium Trial<\/a>.<\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/shinyhunters-possibly-collaborates-with-scattered-spider\/\">ShinyHunters Possibly Collaborates With Scattered Spider in Salesforce Attack Campaigns<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/shinyhunters-possibly-collaborates-with-scattered-spider\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>ShinyHunters Possibly Collaborates With Scattered Spider in Salesforce Attack Campaigns The notorious ShinyHunters cybercriminal group has emerged from a year-long hiatus with a sophisticated new wave of attacks targeting Salesforce platforms across major organizations, including high-profile victims like Google. This resurgence marks a significant tactical evolution for the financially motivated threat actors, who have traditionally [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-6143","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6143"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6143"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6143\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6143"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6143"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6143"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}