Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC5537

Also known as: LdPinch, Judische, the UNC5537 attack, Octo Tempest, UNC3944, SnowSight

Description

UNC5537 is a financially motivated threat actor targeting Snowflake customer databases. They use stolen credentials obtained from infostealer malware to access and exfiltrate large volumes of data. The compromised accounts lack multi-factor authentication, allowing UNC5537 to conduct data theft and extortion.

Goals & Targeting

Targeted Sectors

Financial services
Healthcare
Defense
Telecommunications
Government
Non profit
Gaming
Aviation
Retail
Manufacturing
Utilities
Energy
Transportation
Oil gas
Think tank
Information technology

Targeted Countries / Regions

AU
RU
PL
SA
AE
UA
NL
US

AI Analysis

· 1 week ago

Executive Summary

UNC5537 is a financially motivated threat actor targeting Snowflake customer databases through credential theft and data exfiltration. They exploit weak security measures, such as lack of MFA, to steal credentials and access sensitive information for extortion or sale on the dark web.

Goals & Targeting

UNC5537's strategic objectives appear to be centered on financial gain through data exfiltration and extortion. They target Snowflake customers, suggesting an interest in industries with significant data assets or those that rely heavily on cloud services. The actor likely selects victims based on the ease of access and the perceived value of the stolen data. Their focus on sectors with potentially large datasets aligns with their goal to maximize the profitability of their campaigns.

Enhanced Description

UNC5537 operates with a primary focus on financial gain, leveraging stolen credentials from infostealer malware attacks to infiltrate Snowflake customer databases. The actor specifically targets organizations with insufficient multi-factor authentication (MFA), exploiting this vulnerability to gain unauthorized access. Once inside, UNC5537 exfiltrates large volumes of data, likely for sale or extortion purposes. Their targeting methodology suggests a preference for sectors where sensitive or valuable information is concentrated, and they have demonstrated the ability to adapt their tactics to maximize profit from their operations.

Key Capabilities

  • Credential theft through infostealer malware
  • Data exfiltration from cloud databases
  • Exploitation of weak authentication measures
  • Extortion or sale of stolen data

Software / Tooling

Infostealer malware
Tools for credential dumping
Network exfiltration tools

Campaigns & Victims

UNC5537's campaigns are characterized by their focus on data-rich environments and their reliance on stolen credentials. They target organizations with weak security measures, such as a lack of MFA. Their operational tempo suggests they are methodical, with a focus on maximizing the value of stolen data rather than high-volume attacks.

IOC Patterns

  • Spear-phishing emails targeting Snowflake customers
  • Infostealer malware activity
  • Lack of multi-factor authentication in targeted accounts
  • Unusual database access patterns

Recommended Actions

  • Implement multi-factor authentication for all critical accounts
  • Enhance cloud security by encrypting sensitive data at rest and in transit
  • Monitor network traffic for signs of unauthorized access attempts
  • Conduct regular security audits to identify and patch vulnerabilities

Suggested Tags

Financially motivated
Data theft
Infostealer malware
Snowflake customer targeting

Confidence Assessment

The information available on UNC5537 is limited, with details primarily focused on their financial motivation and targeting methodologies. While their tactics of credential theft and data exfiltration are well-documented in other financially motivated groups, the specific techniques and tools used by this actor remain unclear. There are gaps in understanding their long-term strategic goals, geographic targeting, and potential affiliations.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.huntress.com — Cited by web research for: Judische
  2. cloud.google.com — Cited by web research for: SnowSight
  3. attack.mitre.org — Cited by web research for: T1213.006
  4. attack.mitre.org — Cited by web research for: T1555.001
  5. www.sentinelone.com — Cited by web research for: T1569.002
  6. www.hipaajournal.com — Cited by web research for: CVE-2023-51662

Intel Summary

21

Techniques

40

Tools

0

Campaigns

17

IOCs

0

Observed Data

5

Tactics

Tags

Data Exfiltration
Financially motivated
Data theft
Infostealer malware
Snowflake customer targeting

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.