BCON Collective uncovers shared phishing infrastructure linked to ShinyHunters
Bridewell's BCON Collective traced a routine vishing block to a 100+-domain phishing infrastructure with ShinyHunters links — a reminder that even dismissed alerts can unravel major threat-actor operations.
Summary written by editorial AI · Source link below
Bridewell’s BCON Collective has uncovered an active phishing infrastructure spanning more than 100 malicious domains after investigating what initially appeared to be a routine blocked vishing attempt against one of its customers. The investigation found evidence suggesting the campaign is linked to the ShinyHunters cybercriminal group and revealed that the same phishing kit is being […] The post BCON Collective uncovers shared phishing infrastructure linked to ShinyHunters appeared first on IT
Editorial Analysis
ShinyHunters has a track record of large-scale data breaches; discovery of shared phishing infrastructure suggests ongoing campaigns that European organisations may already be exposed to.
Search your DNS, email-gateway, and proxy logs for the BCON-published domain IOCs and escalate any matches for incident investigation.
A known data-breach group's phishing infrastructure has been mapped across 100+ domains — immediate log review is warranted.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at IT Security Guru in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner2d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d