Defending SaaS-based applications against ShinyHunters OAuth abuse
Between mid-2025 and mid-2026, threat actors using tradecraft associated with ShinyHunters targeted customer SaaS applications, particularly Salesforce instances, through three primary intrusion paths. Voice phishing campaigns impersonated IT support to trick employees into authorizing malicious OAuth applications. Supply chain compromises leveraged trusted integrations including Salesloft, Gainsight, and Klue to obtain OAuth tokens for downstream customer access. Misconfigured guest access enabled exploitation of Aura framework functionality for unauthorized data queries. These techniques abused legitimate OAuth relationships to inherit user and application privileges, enabling enumeration and exfiltration of CRM data while evading authentication detections. The campaigns targeted multiple industries including retail, education, and manufacturing, highlighting risks in OAuth-connected applications and third-party integrations.
AI Analysis
Technical Summary
This campaign involved ShinyHunters-linked threat actors abusing OAuth authorization mechanisms in SaaS applications, primarily Salesforce. The attackers used three main intrusion vectors: (1) voice phishing (vishing) to deceive employees into approving malicious OAuth applications, (2) supply chain compromises of trusted integrations such as Salesloft, Gainsight, and Klue to acquire OAuth tokens for downstream access, and (3) exploitation of misconfigured guest access in the Aura framework to perform unauthorized data queries. By abusing legitimate OAuth relationships, attackers inherited user and application privileges, enabling enumeration and exfiltration of CRM data while bypassing authentication detection controls. The campaign targeted multiple industries, emphasizing the security challenges posed by OAuth abuse and third-party integration vulnerabilities in SaaS environments.
Potential Impact
The abuse of OAuth tokens and legitimate application privileges enabled unauthorized access to sensitive CRM data, including enumeration and data exfiltration. The use of voice phishing and supply chain compromises increased the attack surface and complexity of detection. Multiple industries were affected, potentially resulting in data breaches and loss of customer trust. There were no known exploits in the wild reported at the time of publication.
Mitigation Recommendations
No official patch or fix is available because this is an abuse of legitimate OAuth mechanisms and misconfigurations rather than a software vulnerability. Organizations should strengthen OAuth app authorization processes, enhance employee awareness to prevent voice phishing attacks, audit and secure third-party integrations, and review guest access configurations in frameworks like Aura. Monitoring OAuth app approvals and enforcing strict least-privilege access controls are recommended to mitigate such abuse.
Indicators of Compromise
- ip: 103.75.11.78
- ip: 138.226.246.94
- ip: 212.86.125.24
- ip: 94.154.32.160
- ip: 213.111.148.90
- ip: 103.75.11.110
Defending SaaS-based applications against ShinyHunters OAuth abuse
Description
Between mid-2025 and mid-2026, threat actors using tradecraft associated with ShinyHunters targeted customer SaaS applications, particularly Salesforce instances, through three primary intrusion paths. Voice phishing campaigns impersonated IT support to trick employees into authorizing malicious OAuth applications. Supply chain compromises leveraged trusted integrations including Salesloft, Gainsight, and Klue to obtain OAuth tokens for downstream customer access. Misconfigured guest access enabled exploitation of Aura framework functionality for unauthorized data queries. These techniques abused legitimate OAuth relationships to inherit user and application privileges, enabling enumeration and exfiltration of CRM data while evading authentication detections. The campaigns targeted multiple industries including retail, education, and manufacturing, highlighting risks in OAuth-connected applications and third-party integrations.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This campaign involved ShinyHunters-linked threat actors abusing OAuth authorization mechanisms in SaaS applications, primarily Salesforce. The attackers used three main intrusion vectors: (1) voice phishing (vishing) to deceive employees into approving malicious OAuth applications, (2) supply chain compromises of trusted integrations such as Salesloft, Gainsight, and Klue to acquire OAuth tokens for downstream access, and (3) exploitation of misconfigured guest access in the Aura framework to perform unauthorized data queries. By abusing legitimate OAuth relationships, attackers inherited user and application privileges, enabling enumeration and exfiltration of CRM data while bypassing authentication detection controls. The campaign targeted multiple industries, emphasizing the security challenges posed by OAuth abuse and third-party integration vulnerabilities in SaaS environments.
Potential Impact
The abuse of OAuth tokens and legitimate application privileges enabled unauthorized access to sensitive CRM data, including enumeration and data exfiltration. The use of voice phishing and supply chain compromises increased the attack surface and complexity of detection. Multiple industries were affected, potentially resulting in data breaches and loss of customer trust. There were no known exploits in the wild reported at the time of publication.
Defensive Guidance
No official patch or fix is available because this is an abuse of legitimate OAuth mechanisms and misconfigurations rather than a software vulnerability. Organizations should strengthen OAuth app authorization processes, enhance employee awareness to prevent voice phishing attacks, audit and secure third-party integrations, and review guest access configurations in frameworks like Aura. Monitoring OAuth app approvals and enforcing strict least-privilege access controls are recommended to mitigate such abuse.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.microsoft.com/en-us/security/blog/2026/07/13/defending-saas-based-applications-against-shinyhunters-oauth-abuse/"]
- Adversary
- ShinyHunters
- Pulse Id
- 6a55a1380d4e12c0ea409b6e
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip103.75.11.78 | CC=AU ASN=AS136557 host universal pty ltd | |
ip138.226.246.94 | — | |
ip212.86.125.24 | — | |
ip94.154.32.160 | — | |
ip213.111.148.90 | CC=UA ASN=AS35804 pp sks-lugan | |
ip103.75.11.110 | CC=AU ASN=AS136557 host universal pty ltd |
Threat ID: 6a55f7a868715ace4323278a
Added to database: 07/14/2026, 08:47:36 UTC
Last enriched: 08/13/2026, 12:41:39 UTC
Last updated: 08/27/2026, 16:35:07 UTC
Views: 156
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.