ShinyHunters publicly boasted about breaching ReliaQuest, but the claims appear to be mostly hot air.
In this episode of “What We Missed,” Dark Reading’s Rob Wright and Alex Culafi discuss some of the recent news events and topics that didn’t make it into the publication, starting with ShinyHunters‘ taunting of ReliaQuest.
Last week, the cybersecurity vendor warned of a “widespread ShinyHunters campaign” using spoofed company domains in a now-deleted post on social media platform X. A account associated with ShinyHunters replied with a post that said “Who’s hunting who?” and contained screenshots that appear to be a compromised Okta account for a ReliaQuest employee. The notorious threat group also added ReliaQuest to its data leak site (though the listing only contained a few screenshots).
Later that day, ReliaQuest disclosed that a threat actor successfully vished an employee who entered their credentials into a fake single sign-on (SSO) page. However, the vendor said the attacker has view-only access to its SSO portal, and all attempts to access applications or move laterally were thwarted. So was ReliaQuest really breached?
Also discussed on this episode: New research from Palo Alto Networks’ Unit 42 indicates that AI-generated malware isn’t a prevalent threat — at least, not yet; and two alleged members of the infamous TeamPCP gang were identified and arrested.
What We Missed With Rob Wright & Alex Culafi: Full Transcript
Dark Reading’s Rob Wright: Hello, I’m Rob Wright with Dark Reading.
Dark Reading’s Alex Culafi: And I’m Alex Culafi with Dark Reading.
DR’s Rob Wright: And this is “What We Missed.” This is a discussion about some of the stories that we didn’t get a chance to cover, some of the recent stories, in the pages of Dark Reading — pages, pods, and videos of Dark Reading. And first up, we have Shiny Hunters breaches ReliaQuest — or did they? This was an interesting story, Alex.
DR’s Alex Culafi: Mm-hmm.
DR’s Rob Wright: Last week, ReliaQuest was, I guess, investigating some Shiny Hunters activity. They posted something to Twitter/X about some of the recent social engineering attempts. A threat actor, presumably associated with Shiny Hunters, chimed in and replied to them on social media, on X, and said, “Who’s hunting who?” and appeared to have a photo of, I guess, an Okta portal. Turns out that an employee at ReliaQuest did get phished, and the attacker was able to use those credentials to get into something, but not much, it appears. So what’d you think of this story?
DR’s Alex Culafi: First thing I’ll point out with Shiny Hunters is that Shiny Hunters is often referred to as Shiny Lapsus$ Hunters. And the Lapsus$ part is important because when Lapsus$ popped up, I think it was like 2022, 2023, they were known for doing a lot of these very low-impact breaches where they would either steal some quick source code or get behind the — get in some portal, take a screenshot, do something very low-impact, and then brag about it.
DR’s Rob Wright: Mm-hmm.
DR’s Alex Culafi: They did some other, more substantial, impressive attacks in addition to that, but that was their MO, I think, for their first few months. And this stinks of a Lapsus$-style attack, where yes, in the loosest of terms, they did breach ReliaQuest if you count through its Okta portal, which I would. But it sounds like nothing really happened. And not to go to bat for a vendor, but what I’ll say as something worth possibly celebrating is that the attackers got credentials, got somewhere they shouldn’t, got to a really sensitive part of a network, and weren’t able to do anything, which to me is possibly evidence of zero trust working. Cause it’s not to say no one should ever get attacked or breached. Everyone always will. But what matters a lot of the time is what happens after you do get breached. And it sounds like, based on ReliaQuest’s own reporting, that it was handled. I don’t know. Am I a little too positive on this?
DR’s Rob Wright: No, I think you’re right. And I think some of the initial reactions to this were a little overboard. I know a lot of the stories out there were pretty fair and said that ReliaQuest thwarted the data theft attack or the breach or whatever, that it was a failed attack. And I think that’s more in line with what happened. I mean, ReliaQuest said specifically in their postmortem, which is pretty detailed, and good for them for doing it, that they expect people to get phished. Phishing works, but they had security controls in place that gave the attacker in this case only read-only access to a very limited amount of stuff and nothing sensitive. And they tried to move laterally and couldn’t. So I think that’s a win. And I think that this is just another example of, like, we really need context. Not all breaches are created equally, obviously. And we just need to provide as much context as we can because somebody might read a headline about this story and think that ReliaQuest was really breached, capital B breached, and they were not. So there you have it. What do we got?
DR’s Alex Culafi: Yeah. Yep. This isn’t necessarily a case of Microsoft’s legendary faux pas from 2020 through 2024.
DR’s Rob Wright: Yeah, certainly not. What’s next?
DR’s Alex Culafi: Yeah, Unit 42, Palo Alto Networks’ research wing. I think they’re also sort of the — they’re the threat research. They do some, I think they’re involved in the incident response too. Anyway, they just did a report on malware enabled by AI, whether that means AI-generated code, AI-themed lures, agentic malware concepts. They analyzed 405 malware samples that they could find.
DR’s Rob Wright: Mm-hmm.
DR’s Alex Culafi: And only 12 samples were observed on actual production endpoints protected by their Cortex XDR. 97% never appeared in real-world environments. They were only seen in sandboxes, VirusTotal, or research repositories. And the 12 samples that were seen in production endpoints, all of them were detected and blocked by existing security controls. And their takeaway—not to speak for either of us, but their takeaway—is that yes, malware or AI is enabling faster malware, but a lot of the controls that already exist in place for mature security organizations still generally work. And it was a lot of vibe-coded ransomware that was in the last 12. What do you think?
DR’s Rob Wright: Well, and correct me if I’m wrong, I think one of the things that they noted was that the majority of the AI-generated malware that they found through their detection technology — and obviously it’s not to account for all of the AI-generated malware out there. It’s just the stuff that Unit 42 and Palo Alto saw — but the majority of it was, they thought, sort of like research experiments or maybe early-phase stuff from threat actors or just academic folks kind of playing around with stuff. So I guess this is good news. I remember seeing this and I thought, wow, this is, for all the attention we’ve been putting on sort of AI helping adversaries, one of the things I know that people have been really worried about is what it’s going to do to actual malware development and exploits. And at least in this case, so far, it doesn’t look like it’s having as much of an effect as we thought it might. So that’s good news. I would say that we probably shouldn’t rest on our laurels because we’ve got some frontier models coming that may change that equation quite drastically. But for now, I think this is some sobering research.
DR’s Alex Culafi: Yeah, I feel the same way where they do hedge it a little bit and say, yes, there are a ton of malware samples, but they aren’t really doing anything at this point in time at scale. However, AI does seem to give these threat actors the ability to iterate quickly, which could be a concern in the future. And as you said, means we shouldn’t rest on our laurels. I think it does sort of give credence to the idea that there’s no threat actor abusing a Mythos-level model, rampantly creating all these crazy zero-days, attack chains on old software.
DR’s Rob Wright: Right.
DR’s Alex Culafi: But the research is also kind of a reminder of the bottlenecks that exist. It’s not as simple as finding a crazy exploit and executing it. I mean, executing it is one part of it, but it’s also maintaining persistence.
DR’s Rob Wright: Right.
DR’s Alex Culafi: It’s also monetizing. It’s also staying undetected. Defenders get better, which means malware and attack processes have to get a lot more complex in kind. And I think that’s the heartening side effect to this story to me, which is yes, malware’s a lot more quantity-wise and there could be a severity impact in the future, but it’s not as simple as bad malware means infinite attacks. You know what I mean?
DR’s Rob Wright: Yep, yeah, for sure.
DR’s Alex Culafi: And we got one more, right?
DR’s Rob Wright: We do, we do. More good news, I guess.
DR’s Alex Culafi: Good.
DR’s Rob Wright: So last week, a couple of alleged Team PCP members were arrested. We have Ruben Ian Thomson, 21, and Lewis Michael Gaebler, 23, arrested in Western Australia, I think in the Perth area. Lovely place, by the way. If you ever get a chance to go there, I highly recommend it. And this was a pretty important break because allegedly Thomson is the leader operator, key ringleader.
DR’s Alex Culafi: A leader.
DR’s Rob Wright: Who knows? You never know with these things until, I guess, you do and they admit to it. But anyway, these two guys were arrested. There was a big article in KrebsOnSecurity, which investigated the perpetrators here and connected them to their real identities through different social media, online activities, social media handles, et cetera. There’s a similar report from, I believe, a cybersecurity company, a threat intelligence company, Flare. They just published something, I think last week, that also sort of detailed their investigation into these individuals. And yeah, they’ve been detained, and I believe Thomson was just indicted by the feds here in the US. I don’t know about the other gentleman, but so what do you think?
DR’s Alex Culafi: A clarifying question.
DR’s Rob Wright: Yes.
DR’s Alex Culafi: Are these the Shai-Hulud folks?
DR’s Rob Wright: Well, that’s the question, isn’t it?
DR’s Alex Culafi: Yeah.
DR’s Rob Wright: Yeah. I mean, they might be. I don’t know. There was some discussion, debate about who actually created the Shai-Hulud worm, the mini Shai-Hulud. Was it TeamPCP? Is TeamPCP even a thing? It’s all murky. I would say that they are definitely involved with some supply chain attacks. It’s just sort of triangulating which ones that they’re responsible for that might take some time to sort of really hammer down.
DR’s Alex Culafi: Right. OK. So I think most threat researchers would probably agree that Team PCP was involved in this whole grander process. Some waves, somewhere, somehow, is probably the best assessment that exists.
DR’s Rob Wright: Yes. Mm-hmm.
DR’s Alex Culafi: And for that, that’s great news, right? Assuming that these people did it, assuming that it’s all alleged at this point, but assuming that these are the perpetrators and they did get caught, that’s great news. It would also be awesome if some infrastructure gets taken down as a result of these arrests, cause you know, justice is good.
DR’s Rob Wright: Mm-hmm.
DR’s Alex Culafi: Making it so no one else can get harmed is even better. So yeah, that’s—I don’t know. There’s not a ton for me to say about this otherwise other than seems like good news. What — what did you have anything else about this?
DR’s Rob Wright: Yeah. I — well, just real quick — I think it’s a reminder, number one, that not all cybercriminals and bad actors are from China, Russia, North Korea. This is, I guess, another illustration of English-speaking individuals of the collective group of cybercriminals out there, that they’re involved in this type of stuff, that they do these things. It’s another example of these guys kind of maybe practicing bad opsec, talking a little too much trash, being a little too online, not covering their tracks. I will be interested to see what happens with their pleas, their sentences, what type of time they’re looking at, if they are convicted, if they are in fact the ones that did this stuff. Because the supply chain attacks here were pretty bad. I mean, again, it’s hard to triangulate which ones they are actually responsible for. But, you know, just looking back, the Trivy, the Aqua Security [compromises], there’s a lot of them. They spread really fast, they were very disruptive. Who knows how much sensitive data they got through this stuff? But I think this represents a pretty big break, and I’m glad the authorities, and obviously the cybersecurity community, has made some progress on this. So good news.
DR’s Alex Culafi: Yep.
DR’s Alex Culafi: Australia’s got threat actors too.
DR’s Rob Wright: Yep. And that’s it for this episode of What We Missed. Thanks, Alex.
DR’s Alex Culafi: Thanks, Rob.

No responses yet