ShinyCorp is a cybercriminal entity associated with ShinyHunters and linked in reporting to the ShinySpider (also styled Sh1nySp1d3r or ShinySP1D3R) ransomware-as-a-service ecosystem. It has been described as participating in the monetization of stolen data, including the sale of large breached datasets in cooperation with ransomware partners and other e-crime actors. Reporting also associates the broader cluster with extortion activity involving theft of victim data, pressure through public leaking of samples, and seven-figure payment demands. Activity attributed to this cluster includes targeting enterprise identity infrastructure and single sign-on environments, as well as operations affecting retail, aviation, and telecommunications organizations. The associated ransomware capability has been described as focusing on VMware ESXi environments to enable large-scale encryption of virtualized infrastructure. Additional tactics reported for the broader associated actors include voice-phishing-enabled initial access, supply-chain compromise, insider recruitment, and collaboration with other criminal communities including actors tied to Scattered Spider and The Com. At high confidence from the available information, ShinyCorp appears financially motivated and involved in data theft and extortion-oriented cybercrime rather than state-directed operations. The relationship between ShinyCorp, ShinyHunters, and ShinySpider is reported as close, but the precise organizational boundaries and whether ShinyCorp is a distinct group, sub-group, or brand are not fully resolved from the available information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.