Cybersecurity

ShinyHunters and the SLSH Supergroup Launch Coordinated Attacks on Enterprise Identity Systems

February 19, 20263 min read

A highly coordinated identity-focused attack campaign is actively targeting more than 100 major enterprises, including Canva, Atlassian, Epic Games, HubSpot, and Zoom — and it’s bypassing even hardened MFA defenses.

At the center of this activity is ShinyHunters, operating as part of a broader threat alliance known as SLSH — a “supergroup” formed from the combined capabilities of Scattered Spider, LAPSUS$, and ShinyHunters.

This is not automated phishing.
It is human-led, real-time identity compromise — and it’s aimed squarely at Single Sign-On (SSO) platforms, particularly Okta.


🎭 The SLSH Supergroup Explained

Threat intelligence firm Silent Push has identified a surge in infrastructure that mirrors the tactics, techniques, and procedures (TTPs) historically used by SLSH actors.

What makes this campaign especially dangerous is its hybrid approach:

  • Advanced technical tooling

  • Highly persuasive voice phishing (vishing)

  • Live manipulation of authentication flows

Rather than blasting emails at scale, attackers engage victims directly — adapting their approach in real time based on each organization’s login process and MFA configuration.


🔑 How the Attack Works: Live Identity Theft

The campaign centers on a “Live Phishing Panel”, a tool that allows attackers to:

  • Intercept credentials and MFA tokens in real time

  • Control phishing pages dynamically during active login sessions

  • Gain immediate, persistent access to enterprise environments

While one operator manipulates the phishing interface, another may be:

  • Calling employees

  • Contacting IT help desks

  • Posing as internal staff or contractors

This synchronized human interaction allows attackers to defeat MFA methods that rely on user approval — even in mature security environments.


🎯 Who Is Being Targeted

Silent Push has observed active targeting or infrastructure preparation within the last 30 days across multiple sectors:

Technology

  • Atlassian

  • Canva

  • Epic Games

  • HubSpot

  • Zoom

Financial Services

  • Blackstone

  • RBC

  • State Street

Healthcare

  • Biogen

  • Moderna

Real Estate & Infrastructure

  • Simon Property Group

  • Zillow

  • AECOM

  • Halliburton

Once an SSO account is compromised, it effectively becomes a skeleton key — unlocking access to cloud apps, internal tools, and sensitive data across the enterprise.


🚨 Attack Progression: From Access to Extortion

Following the LAPSUS$ playbook, the attackers move fast:

  1. Initial SSO compromise via vishing and live phishing

  2. Lateral movement into internal communication platforms (Slack, Microsoft Teams)

  3. Social engineering of administrators to escalate privileges

  4. Rapid data exfiltration

  5. Ransomware deployment and extortion

The goal isn’t persistence — it’s speed and leverage.


🛡️ Why Traditional Defenses Fail

Standard security awareness training alone is insufficient against this threat.

SLSH operators are:

  • Highly trained in persuasion

  • Coordinated across multiple attack roles

  • Adaptive to each victim’s environment

MFA that depends on human approval can be socially engineered. Once an attacker gains SSO access, technical controls often fall too late.


🔐 What Organizations Must Do Now

Elliptic Systems recommends immediate action for organizations at risk:

  • 🚨 Alert employees and help desk staff about active vishing campaigns

  • 🔍 Audit Okta and SSO logs, especially:

    • “New Device Enrolled” events

    • Followed immediately by logins from unfamiliar IP addresses

  • 🔐 Transition to phishing-resistant authentication (FIDO2, passkeys)

  • 🌐 Deploy pre-attack intelligence to identify malicious lookalike domains before they go live

Silent Push’s Indicators of Future Attack (IOFA™) demonstrate how DNS-level intelligence can block attacker infrastructure before exploitation begins.


🔎 The Elliptic Systems Perspective

This campaign reinforces a critical reality:

Identity is the new perimeter — and humans are the entry point.

When attackers combine live social engineering with real-time technical control, prevention must begin before credentials are entered.

At Elliptic Systems, we help organizations:

  • Harden identity and SSO platforms

  • Simulate vishing attacks against real workflows

  • Deploy phishing-resistant authentication

  • Detect attacker infrastructure early — not after compromise

Waiting for a breach notification is no longer an option.

👉 Schedule an Identity Threat Readiness Assessment


⚠️ Final Takeaway

The SLSH supergroup doesn’t break in.
They talk their way in — then move fast.

If a single SSO account can unlock your enterprise,
your identity security must be unphishable by design.

Elliptic Systems — Securing Identity Before Attackers Reach Your People.

Eric Stefanik

Eric Stefanik

Ai Consultant | Best-selling Author | Speaker | Innovator | Leading Cybersecurity Expert

LinkedIn logo icon
Instagram logo icon
Youtube logo icon
Back to Blog