HomeSecurityMandiant: How ShinyHunters Abuses SSO to Steal Cloud Data

Mandiant: How ShinyHunters Abuses SSO to Steal Cloud Data

A new, highly sophisticated wave of attacks targeting enterprise SaaS environments is being brought to light by Google Threat Intelligence Group through Mandiant. At the center is the notorious ShinyHunters and other hacking groups, which are using a combination of vishing (voice phishing) techniques and well-designed phishing websites to bypass security mechanisms and steal SSO credentials and MFA codes.

ShinyHunters SSO cloud

When IT… calls

According to the analysis, attackers convincingly impersonate IT or helpdesk staff and call employees . Under the pretext of urgent changes to multifactor authentication, they guide victims to phishing pages that perfectly mimic their organizations’ official login portals. The difference is interactivity :advanced phishing kits allow perpetrators to “walk” the victim through the processin real time, while they are still on the phone.

See also: CERT Polska: Details on cyberattacks on wind and photovoltaic parks

Real-time MFA bypass

Okta confirms that these attacks don’t stop at simply stealing passwords . Attackers then immediately pass on the stolen credentials, trigger legitimate MFA challenges , and instruct the user to approve push notifications or enter OTPs . This not only gains access, but also enrolls their own devices as trusted , ensuring a persistent presence.

SSO as a central looting point

Once an account is compromised, the SSO dashboard becomes a treasure map. Through Okta, Microsoft Entra, or Google SSO, attackers gain access to a multitude of SaaS applications: Salesforce, Microsoft 365, SharePoint, Slack, DocuSign, Google Drive, Atlassian, and many more. For groups aiming to steal data and extort money, a single account is enough to open the door to a company’s entire cloud ecosystem.

See also: Guide for Businesses and SMBs: How to Prepare for Cyberattacks

Mandiant: How ShinyHunters Abuses SSO to Steal Cloud Data

Multiple clusters, common methodology

Mandiant is tracking activity across different threat clusters: UNC6661, UNC6671 , and UNC6240 (ShinyHunters). UNC6661 appears to be responsible for the initial attacks, with opportunistic targeting and mass data extraction, while the extortion attacks are attributed to ShinyHunters. Meanwhile, UNC6671 uses a similar vishing model, but with more aggressive pressure tactics and without adopting the ShinyHunters brand.

Traces, logs and attempts at concealment

The technical traces of the attacks are revealing: file downloads from SharePoint and OneDrive with PowerShell user-agents, suspicious connections to Salesforce from recognized IPs, and bulk document exports from DocuSign. In at least one case, the perpetrators activated the ToogleBox Recall in Google Workspace to detect and delete MFA notification emails, trying to eliminate any warning signs to the victim.

Phishing domains that look… legitimate

Phishing domains follow specific naming patterns, such as companynamesso[.]com or companynameinternal[.]com, impersonating corporate portals, helpdesks, or identity providers. A typical example is matchinternal[.]com, which was linked to the recent Match Group breach.

See also: EDR vs Antivirus: What a modern business really needs

Mandiant: How ShinyHunters Abuses SSO to Steal Cloud Data

What should organizations do?

Mandiant urges network defenders to focus on behavioral detections: rapid data extraction after an SSO breach, unexpected PowerShell use in cloud services, unexpected OAuth authorizations, and deletions of MFA notification emails.

At the same time, it published detailed hardening, logging and detection recommendations and special rules for Google SecOps, emphasizing that the battle for SaaS security now involves user education and early detection, not just technology.

Source: www.bleepingcomputer.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS