INTEL_REPORT
Mandiant / Google Threat Intelligence Blog · published 1/30/2026, 2:00:00 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Vishing for Access: Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft Introduction Mandiant has identified an expansion in threat activity that uses tactics, techniques, and procedures (TTPs) consistent with prior ShinyHunters-branded extortion operations. These operations primarily leverage sophisticated voice phishing (vishing) and victim-branded credential harvesting sites to gain initial access to corporate environments by obtaining single sign-on (SSO) cred…
https://cloud.google.com/blog/topics/threat-intelligence/expansion-shinyhunters-saas-data-theft
sha256:b14b156d956dacce560fc1091c53dea89b93265629457b6bfa76160bf29f1c14
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| Open → |
| ip | 157.131.172.74 | Open → |
| ip | 67.21.178.234 | Open → |
| ip | 142.127.171.133 | Open → |
| ip | 76.70.74.63 | Open → |
| ip | 206.170.208.23 | Open → |
| ip | 68.73.213.196 | Open → |
| ip | 37.15.73.132 | Open → |
| ip | 104.32.172.247 | Open → |
| ip | 85.238.66.242 | Open → |
| ip | 199.127.61.200 | Open → |
| ip | 209.222.98.200 | Open → |
| ip | 38.190.138.239 | Open → |
| ip | 198.52.166.197 | Open → |
| domain | sso.com | Open → |
| domain | internal.com | Open → |
| domain | index.jsp | Open → |
| domain | my.salesforce.com | Open → |
| domain | apps.googleusercontent.com | Open → |
| domain | www.googleapis.com | Open → |
| domain | gmail.addons.current.message.readonly | Open → |
| domain | gmail.addons.execute | Open → |
| domain | script.locale | Open → |
| domain | userinfo.email | Open → |
| domain | tutanota.com | Open → |
| domain | onionmail.com | Open → |
| domain | support.com | Open → |
| domain | okta.com | Open → |
| domain | azure.com | Open → |
| domain | zendesk.com | Open → |
| domain | access.com | Open → |
| domain | acess.com | Open → |
| domain | policy.rule | Open → |
| domain | user.session | Open → |
| domain | e.extracted.fields | Open → |
| domain | debugcontext.debugdata.tunnels | Open → |
| domain | e.target.resource.name | Open → |
| domain | mullvad.vpn | Open → |
| domain | e.network.http | Open → |
| domain | e.target.application | Open → |
| domain | e.principal.application | Open → |
| domain | e.target.file | Open → |
| domain | re.capture | Open → |
| domain | strings.coalesce | Open → |
| domain | e.additional.fields | Open → |
| domain | e.network.email.subject | Open → |
| url | https://www.googleapis.com/auth/gmail.addons.current.message.readonly | Open → |
| url | https://www.googleapis.com/auth/gmail.addons.execute | Open → |
| url | https://www.googleapis.com/auth/script.external_request | Open → |
| url | https://www.googleapis.com/auth/script.locale | Open → |
| url | https://www.googleapis.com/auth/userinfo.email | Open → |