How a Fortune 500 media company blocked a Scattered Lapsus ShinyHunters attack using infrastructure flagged 24 hours before it launched

customer story

Industry: Media and Entertainment
Role: Security Operations
Use case: Indicators of Future Attack, adversary infrastructure enumeration, firewall blocking, campaign monitoring


A Fortune 500 media and entertainment company stopped a Scattered Lapsus ShinyHunters attack in real time, because Silent Push had already flagged the infrastructure one day before the attack launched.


+24hrs
Early warning
Silent Push flagged the domain before the attack launched
100%
Infrastructure mapped
Full adversary infrastructure enumerated and pushed to firewall within minutes
2
Attempts blocked
Second attack blocked before it reached an employee

Scattered Lapsus ShinyHunters: how they operate

Scattered Lapsus ShinyHunters is a financially motivated threat actor group responsible for breaches at some of the largest organisations in the world. Their approach combines repeatable social engineering with bulletproof hosting infrastructure and lookalike domains built for credential harvesting.

Their tactics are well documented. Their infrastructure is not. It is built fresh for each campaign, stood up close to the time of the attack, and designed to avoid detection by tools that rely on historical indicators. Tracking it requires visibility into adversary infrastructure during the staging phase, before the campaign goes live.

The incident

The threat actor placed a call to an employee at the organisation, directing them to a lookalike domain impersonating a passkey authentication flow. The domain was live and the attack was in progress.

The organisation’s existing tooling, CrowdStrike, caught the outbound connection attempt in firewall logs. The team ran it through Silent Push to confirm it was an IOFA. The domain was blocked, but the immediate question was larger: how much infrastructure had Scattered Lapsus ShinyHunters already staged for this campaign? Were other employees being targeted via different domains at the same time?

Without visibility into the adversary’s full infrastructure, there was no way to know.

The domain was already flagged

Silent Push had identified the domain one day before the attack launched. It was part of a known bulletproof hosting cluster, tracked and tagged in a Silent Push Indicators of Future Attack® feed. The domain had been flagged as adversary infrastructure before the threat actor placed the call.

Indicators of Future Attack Feed Card

When the outbound connection appeared in the team’s environment, they used Silent Push to enumerate the full infrastructure Scattered Lapsus ShinyHunters had staged for the campaign. Every related domain was identified and pushed into their CrowdStrike firewall within minutes.

Second attempt, already blocked.

Fifteen minutes after the initial domain was blocked, the same group attempted a second social engineering attack against a different employee using a different domain. That domain was already blocked. The attempt failed before it reached the employee.

The team then used Silent Push to monitor every domain the group had staged for the campaign on an ongoing basis, ensuring no further attempts would reach anyone in the organisation.

IOCs vs IOFAs: what the difference looks like in practice

Traditional threat feeds deliver indicators of compromise: forensic evidence of what happened after a breach. By the time an IOC is published and ingested, the event it describes has already occurred. The infrastructure has often been rotated or taken down.

Silent Push delivers Indicators of Future Attack®: signals from adversary infrastructure being built before it is used. In this case, that meant a domain flagged inside a bulletproof hosting IOFA feed, 24 hours before the threat actor used it in an active campaign.

That window, between infrastructure being staged and infrastructure being weaponised, is where preemptive defense is actually possible. The domain was known and the cluster was mapped. When the attack launched, the response was already in place.


To see how Silent Push IOFA feeds and the broader platform works in practice, book a demo with our platform experts.