Back to Feed
Threat IntelligenceMar 12, 2026

Unit42-timely-threat-intel/2026-03-12-Vishing-Campaigns-Lead-to-Data-Theft-and-Extortion.txt at main · PaloAltoNetworks/Unit42-timely-threat-intel

Since late December 2025, Unit 42 has tracked vishing campaigns attributed to BlingLibra (ShinyHunters) and affiliated threat actors targeting multiple industries, resulting in data theft and extortion incidents. The campaign involves social engineering attacks designed to compromise credentials and facilitate unauthorized data access.

Summary

Since late December 2025, Unit 42 has tracked vishing campaigns attributed to BlingLibra (ShinyHunters) and affiliated threat actors targeting multiple industries, resulting in data theft and extortion incidents. The campaign involves social engineering attacks designed to compromise credentials and facilitate unauthorized data access.

Indicators of Compromise

  • malware — BlingLibra
  • malware — ShinyHunters