As cited
Copy frozen at (site build).
threat intel
How a Fortune 500 media company blocked a Scattered Lapsus ShinyHunters attack using infrastructure flagged 24 hours before it launched
A Fortune 500 media company blocked a Scattered Lapsus ShinyHunters attack using infrastructure that Silent Push had flagged 24 hours before the campaign launched. The threat actor group conducted a social engineering attack directing an employee to a lookalike domain, but the organization used Silent Push to enumerate the full adversary infrastructure and block all related domains within minutes, stopping both the initial and a subsequent attack attempt. The case demonstrates the value of tracking adversary infrastructure during the staging phase rather than relying solely on post-incident indicators.
Why it matters: Media, entertainment, and other Fortune 500 companies are targeted by Scattered Lapsus ShinyHunters for credential harvesting; practitioners should consider infrastructure threat intelligence that detects adversary staging activity before attacks launch, rather than waiting for forensic evidence after compromise.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
How a Fortune 500 media company blocked a Scattered Lapsus ShinyHunters attack using infrastructure flagged 24 hours before it launched
A Fortune 500 media company detected and blocked two credential-harvesting attacks from the Scattered Lapsus ShinyHunters group using infrastructure intelligence flagged 24 hours before the threat actor launched the campaign. The attacks used lookalike domains in social engineering calls to employees, with the initial domain identified in firewall logs and subsequently enumerated for full campaign infrastructure. All related domains were blocked proactively before reaching their targets.
Why it matters: Media and entertainment organizations face credential-harvesting attacks from financially motivated threat actors using fresh infrastructure for each campaign; defenders need visibility into adversary staging infrastructure before attacks launch to block campaigns preemptively rather than reacting to observed compromise.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
How a Fortune 500 media company blocked a Scattered Lapsus ShinyHunters attack using infrastructure flagged 24 hours before it launched
A Fortune 500 media company detected and blocked two credential-harvesting attacks from the Scattered Lapsus ShinyHunters group using infrastructure intelligence flagged 24 hours before the threat actor launched the campaign. The attacks used lookalike domains in social engineering calls to employees, with the initial domain identified in firewall logs and subsequently enumerated for full campaign infrastructure. All related domains were blocked proactively before reaching their targets.
Why it matters: Media and entertainment organizations face credential-harvesting attacks from financially motivated threat actors using fresh infrastructure for each campaign; defenders need visibility into adversary staging infrastructure before attacks launch to block campaigns preemptively rather than reacting to observed compromise.
- Source published
- First seen by Cybersecurity Tracker