OTSecurity

Health-ISAC warns ShinyHunters targets health sector with vishing, credential theft and MFA bypass tactics


Health-ISAC is warning that the ShinyHunters cybercrime group is actively targeting the global health sector with highly targeted voice phishing campaigns and medical-themed impersonation domains designed to steal corporate credentials. Observed campaigns have targeted employees through calls, voicemails and mass emails, directing them to look-alike login pages that can enable unauthorized access to enterprise systems. This comes as recent activity included successful attempts to bypass multifactor authentication and move from single sign-on platforms into connected cloud applications. 

Threat activity reflects a shift toward identity and software-as-a-service access as a means of data theft and extortion, according to Health-ISAC. Once credentials are obtained, ShinyHunters can use reverse-proxy phishing techniques to capture active MFA tokens or push approvals, allowing attackers to establish web sessions and pivot into services including Microsoft 365, SharePoint and Salesforce. Health-ISAC said the actors are using newly registered domains that incorporate targeted company names and variable endings, with some domains using .claim and .claims top-level domains. 

“Over the past two weeks, Health-ISAC has issued warnings to several health sector organizations after observing persistent, highly targeted vishing campaigns. These campaigns attempt to trick users into exposing their credentials on malicious sites that mimic legitimate login pages, thereby facilitating unauthorized initial access,” the organization said in its recent threat alert. “Recent observations indicate that threat actors—specifically tied to the ShinyHunters extortion group—are reaching employees directly on personal mobile devices via calls and voicemails, as well as emailing users en masse from multiple random accounts.” 

It added that the recent registration of medical-themed domains indicates an expanding scope targeting health operations and specialized business units, underscoring the intent to establish persistent initial access across diverse enterprise sectors.

“For ShinyHunters, the SSO platform is the control plane. Once an identity is compromised, the actors rapidly pivot from the central identity provider (IdP) dashboard into connected SaaS platforms (such as Microsoft 365, SharePoint, and Salesforce) to exfiltrate sensitive data and internal communications,” according to the alert. “This data theft at a cloud scale provides the necessary leverage for their subsequent extortion demands. The primary operational pattern identified across these infrastructure registrations is the use of the newly registered domains prefixed with the target company’s name, followed by variable endings tailored to specific phishing lures.” 

It mentioned that these campaigns pose a severe risk of compromised credentials, multi-factor authentication (MFA) bypass, and subsequent unauthorized access to corporate infrastructure and cloud SaaS platforms. Observed threat activity highlights a highly organized, adaptive threat actor executing broad social engineering campaigns to acquire valid corporate credentials and active MFA tokens. Recent campaigns have shown that ShinyHunters is behaving less like a traditional ransomware group and more like an identity- and SaaS-access extortion operation. 

“In the initial phases, the actors likely rely heavily on pre-operational reconnaissance, conducting extensive research on targeted employees and the specific internal departments (such as IT help desks or legal operations) they choose to impersonate,” the alert said. “By spoofing known organizational phone numbers, callers establish immediate trust and exploit staff’s natural inclination to assist internal support functions. Furthermore, ShinyHunters actors have been observed acting aggressively, frequently utilizing follow-up voicemails to pressure targets into compliance and instructing users to bypass corporate security controls by navigating to malicious links on personal devices.” 

Additionally, once the user submits their credentials on the phishing site, the threat actor uses reverse-proxy phishing kits to submit them to the legitimate corporate login portal in real time. The victim is then prompted over the phone to provide their active MFA token or to accept a push notification, granting the attacker an active web session.

The organization called upon asset owners and operators to increase situational awareness and prevent exploitation and disruption of their security apparatus. Block the [dot]claim and [dot]claims top-level domains within the organization unless they are legitimate infrastructure. 

The alert recommends implementing targeted security awareness training to educate employees about modern social engineering tactics, including aggressive vishing calls and voicemail lures. Employees should also be trained to identify look-alike domains and safely verify communications that appear to come from internal IT teams.

Organizations should enforce device-context verification by restricting SaaS applications, internal portals and APIs to corporate-managed devices that have been verified through client certificates, EDR health checks or MDM profiles. Identity verification alone is insufficient and should be supported by a defense-in-depth security architecture.

Organizations should transition to phishing-resistant multifactor authentication, prioritizing FIDO2/WebAuthn security keys or passkeys for administrators and other high-risk groups. SMS and voice-based MFA, along with weak fallback methods, should be disabled or tightly restricted. Helpdesk and MFA reset workflows should require strict identity verification. Employees should also be trained that IT will not reset MFA in response to inbound calls.

Organizations should monitor look-alike infrastructure by tracking newly registered domains, newly observed domains and branded subdomains that target corporate single sign-on services. Session management should include timeouts that support normal user workflows while maintaining security, restrict identity provider visibility for noncompliant endpoints, and generate alerts for simultaneous logins from anomalous geographies or IP addresses.



Source link