Behind the Panels: Validating ShinyHunters Cluster A Infrastructure Through Network Telemetry

Behind the Panels: Validating ShinyHunters Cluster A Infrastructure Through Network Telemetry
Team Cymru validated active Cluster A phishing infrastructure linked to Push Security’s research on ShinyHunters and BlackFile, confirming Mevspace-hosted domains, a Doko-branded artifact, and recurring victim-themed naming patterns. The analysis surfaced more than 40 additional domains and highlighted how phishing panels are built from hosted infrastructure, certificates, exposed services, and reusable deployment patterns. #ShinyHunters #BlackFile #DokoPanel #Mevspace #UNC6240 #UNC6661

Keypoints

  • Team Cymru independently validated infrastructure consistent with Push Security’s Cluster A phishing panel reporting.
  • The activity was hosted on Mevspace AS201814 and matched a registrar/nameserver fingerprint tied to Cluster A.
  • Two active IPs, 149.50.97.174 and 149.50.127.228, were identified as consistent with the cluster; a third shared-hosting IP was excluded.
  • More than 40 victim-themed domains were found, targeting identity providers, higher education, financial services, retail, cryptocurrency platforms, and other high-value services.
  • A Doko-branded artifact, dokopanel.com, was found on the same infrastructure and provided a useful pivot point, though not attribution proof.
  • Certificate, TLS, passive DNS, and exposed-service observations added hunting context, including a BT-Panel self-signed certificate on port 21.
  • The report emphasizes that passive telemetry confirms infrastructure patterns but does not independently attribute the activity to a specific actor or individual.

MITRE Techniques

  • [T1566 ] Phishing – Used convincing login pages and lure domains to capture credentials and MFA by directing victims to brand-themed pages (‘the victim is typically directed to a domain that looks like an internal identity, support, passkey, or SSO page’).
  • [T1656 ] Credentials Phishing – Captured enterprise identity credentials through fake identity/provider pages (‘voice phishing with adversary-in-the-middle credential capture’).
  • [T1567.004 ] Exfiltration to Cloud Storage – The campaign aimed to steal access for SaaS environments such as Salesforce, SharePoint, Slack, and DocuSign (‘once credentials and MFA are captured, the operator can attempt to access identity providers and pivot into connected SaaS environments’).
  • [T1583.001 ] Acquire Infrastructure: Domains – Registered numerous lure domains with victim-themed naming patterns (‘domains observed on 149.50.97.174… mydisneysso.com… myupennmanager.com…’).
  • [T1583.004 ] Acquire Infrastructure: Server – Hosted phishing infrastructure on Mevspace AS201814 and related servers (‘Mevspace AS201814 as the hosting provider for Cluster A’).
  • [T1071.001 ] Application Layer Protocol: Web Protocols – Delivered phishing content over HTTP/HTTPS and Cloudflare-fronted infrastructure (‘Cloudflare CDN peers… on ports 80 and 443’).
  • [T1090.002 ] Proxy: External Proxy – Used Cloudflare as fronting infrastructure to gate victim traffic (‘traffic reaching Cloudflare-fronted lure infrastructure’).
  • [T1036 ] Masquerading – Disguised domains as internal or trusted brand services (‘myyalemanager.com’, ‘amazoninternal.com’, and other victim-themed names).
  • [T1078 ] Valid Accounts – The objective was to steal and reuse credentials for SaaS and identity access (‘Once credentials and MFA are captured, the operator can attempt to access identity providers’).

Indicators of Compromise

  • [IP addresses ] Mevspace-hosted Cluster A infrastructure – 149.50.97.174, 149.50.127.228
  • [IP address ] Excluded shared-hosting node observed during discovery – 149.86.225.36
  • [Domains ] Victim-themed and operator-associated domains on 149.50.97.174 – mydisneysso.com, myyalemanager.com, cp.myyalemanager.com, amazoninternal.com, and other 30+ domains
  • [Domains ] Crypto-focused and branded domains on 149.50.127.228 – crypto-ato.com, account-ndax.com, 412721coinbase.com, dokopanel.com, and other related domains
  • [Certificate serial number ] Self-signed BT-Panel certificate on 149.50.97.174 port 21 – 58:23:e9:3d:a7:48:1e:3e:7f:5c:85:12:15:d9:63:0c:f4:6e:f2:06
  • [TLS / JA3 hashes ] Hunting fingerprints referenced in the article – 7291ea5e449f2c7b17582541703e549d, 15af977ce25de452b96affa2addb1036
  • [Client-side hashes ] Push Security published phishing kit indicators – 8a01bcb70ec1c101a163c9cb8e074781c1322096f7ae01789f02252854def44cf574b6e6b3a968cda5f51bec2c090d8eb095fbcfc383314f94bc15676a0d6692, c0df36ccf88d5c8434b13b58f7a55a9715643a126148b9d078a93075d09cad26d178dc7108fa9344dae28e350e810352e9e874563496dc7876ee628b11b0eabb9c0939960e49122196e44b6779fe55dd7a13ab437ce251c8cf35f8c6daf8be21e8128b33259f7ea4313c942689ba0ba557f17b1474f2e621c62a5b77674fab86, and 2 more hashes
  • [ASNs ] Hosting infrastructure referenced in the report – AS201814, AS39287


Read more: https://www.team-cymru.com/post/validating-shinyhunters-cyber-threat-actors-infrastructure