ShinyHunters Phishing Infrastructure: 100+ Malicious Domains Uncovered
The BCON Collective's investigation reveals how a single blocked vishing attempt can be the tip of a much larger, coordinated phishing operation — in this case linked to the prolific ShinyHunters group operating over 100 malicious domains. The root cause lies in insufficient user awareness and detection capabilities that allow sophisticated social engineering campaigns to operate at scale before being identified. Phishing and vishing attacks exploit human trust, making them effective even against technically hardened organisations. The ShinyHunters connection underscores that modern phishing infrastructure is professionalised, reusable, and shared across criminal networks, amplifying its reach and impact. Early detection and threat intelligence sharing, as demonstrated here, are critical to disrupting these campaigns before significant harm occurs.
Tactical Insight
Immediate actions
- Deploy DNS filtering and threat intelligence feeds to block known malicious domains in real time.
- Report and escalate any suspected vishing or phishing attempts immediately to your security team for rapid investigation.
- Perform a retroactive log review to identify any employees or systems that may have interacted with the identified malicious domains.
Long-term improvements
- Conduct regular, role-tailored security awareness training that includes vishing and phishing simulation exercises.
- Subscribe to threat intelligence sharing communities (e.g., ISACs, BCON Collective advisories) to receive early warnings about emerging phishing infrastructure.
- Implement email authentication standards (DMARC, DKIM, SPF) across all organisational domains to reduce spoofing risk.
Detection measures
- Establish continuous monitoring of DNS query logs to detect connections to newly registered or suspicious domains.
- Integrate endpoint and network telemetry into a SIEM to correlate phishing-related indicators of compromise (IoCs) at scale.
- Set up automated alerts for anomalous outbound communication patterns that may indicate successful phishing compromise.