← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Vishing for Access: Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft
Mandiant has reported a significant uptick in activities by threat actors associated with the ShinyHunters brand, particularly focusing on sophisticated vishing techniques and the use of credential harvesting websites to infiltrate corporate environments. The primary objective of these operations is to gain access to sensitive corporate data, particularly from cloud-based software-as-a-service (SaaS) applications, which the threat actors subsequently exfiltrate for extortion purposes.
The threat group UNC6661 has been active from early to mid-January 2026, impersonating IT staff to manipulate employees into providing their single sign-on (SSO) credentials and multi-factor authentication (MFA) codes. This was accomplished by directing victims to phishing sites that replicated the branding of their organizations. The phishing domains associated with UNC6661 typically followed a naming pattern such as http://companynamesso.com or http://companynameinternal.com, being registered with NICENIC.
MITRE ATT&CK & Malware Families
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| CVE | CVE-2025-8088 | — | 2026-02-01 | |
| domain | access.com | — | 2026-02-01 | |
| domain | acess.com | — | 2026-02-01 | |
| domain | event.security | — | 2026-02-01 | |
| domain | internal.com | — | 2026-02-01 | |
| domain | support.com | — | 2026-02-01 | |
| domain | userinfo.email | — | 2026-02-01 | |
| shinycorp@tutanota.com | — | 2026-02-01 | ||
| shinygroup@onionmail.com | — | 2026-02-01 | ||
| hostname | e.target.resource.name | — | 2026-02-01 |