Also known as: LdPinch, Judische, the UNC5537 attack, Octo Tempest, UNC3944, SnowSight
UNC5537 is a financially motivated threat actor targeting Snowflake customer databases. They use stolen credentials obtained from infostealer malware to access and exfiltrate large volumes of data. The compromised accounts lack multi-factor authentication, allowing UNC5537 to conduct data theft and extortion.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNC5537 is a financially motivated threat actor targeting Snowflake customer databases through credential theft and data exfiltration. They exploit weak security measures, such as lack of MFA, to steal credentials and access sensitive information for extortion or sale on the dark web.
Goals & Targeting
UNC5537's strategic objectives appear to be centered on financial gain through data exfiltration and extortion. They target Snowflake customers, suggesting an interest in industries with significant data assets or those that rely heavily on cloud services. The actor likely selects victims based on the ease of access and the perceived value of the stolen data. Their focus on sectors with potentially large datasets aligns with their goal to maximize the profitability of their campaigns.
Enhanced Description
UNC5537 operates with a primary focus on financial gain, leveraging stolen credentials from infostealer malware attacks to infiltrate Snowflake customer databases. The actor specifically targets organizations with insufficient multi-factor authentication (MFA), exploiting this vulnerability to gain unauthorized access. Once inside, UNC5537 exfiltrates large volumes of data, likely for sale or extortion purposes. Their targeting methodology suggests a preference for sectors where sensitive or valuable information is concentrated, and they have demonstrated the ability to adapt their tactics to maximize profit from their operations.
Key Capabilities
Software / Tooling
Campaigns & Victims
UNC5537's campaigns are characterized by their focus on data-rich environments and their reliance on stolen credentials. They target organizations with weak security measures, such as a lack of MFA. Their operational tempo suggests they are methodical, with a focus on maximizing the value of stolen data rather than high-volume attacks.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The information available on UNC5537 is limited, with details primarily focused on their financial motivation and targeting methodologies. While their tactics of credential theft and data exfiltration are well-documented in other financially motivated groups, the specific techniques and tools used by this actor remain unclear. There are gaps in understanding their long-term strategic goals, geographic targeting, and potential affiliations.
No campaigns linked yet.
No observed data linked yet.
21
Techniques
40
Tools
0
Campaigns
17
IOCs
0
Observed Data
5
Tactics