Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC6395

Also known as: tracked as, UNC6040, UNC6240

Description

UNC6395 targets a wide range of industries—including finance, telecommunications, education, government, manufacturing, and healthcare—across multiple countries such as the United Kingdom, Russia, China, Vietnam, Brazil, and the United States. The actor routinely exploits OAuth tokens issued to Salesforce organizations, either via open‑source credential scanners like TruffleHog or through compromised third‑party integrations such as Salesloft Drift, in order to gain read access to thousands of Salesforce instances. Once inside, UNC6395 deploys custom scripts that mimic the official Data Loader and utilizes modified browser extensions (e.g., AuraInspector) to expand its foothold across Experience Cloud environments. The group then performs large‑volume API queries to exfiltrate hundreds of millions of Salesforce records, often targeting sensitive items such as AWS access keys, Snowflake tokens, and user passwords. Beyond data theft, the actor employs voice‑based phishing (vishing) delivered over anonymizing networks like Mullvad VPN or Tor to coerce victims into authorizing malicious tools and credentials. It also issues extortion demands tied to potential public leaks of exfiltrated information, adding a ransomware component to its revenue model.

Goals & Targeting

Targeted Sectors

Financial services
Telecommunications
Education
Retail
Critical infrastructure
Defense
Government
Manufacturing
Gaming
Healthcare
Transportation

Targeted Countries / Regions

GB
RU
CN
VN
BR
US

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

UNC6395, also known as ShinyHunters, is a financially motivated threat actor that leverages OAuth token theft, misconfigured Salesforce Experience Cloud, and voice‑based phishing to exfiltrate massive volumes of data from over 700 organizations worldwide. Using legitimate API endpoints and custom Python scripts, the group harvests credentials such as AWS keys and Snowflake tokens, then threatens victims with extortion if their data is leaked. The actor’s operations combine supply‑chain compromise, lateral movement, and extortion tactics to maximize financial gain.

Goals & Targeting

UNC6395’s strategic objectives center on financial gain through the collection and monetization of high‑value identity and access data. By harvesting OAuth tokens, AWS keys, and other privileged credentials, the actor positions itself to facilitate credential stuffing, lateral movement, or direct financial theft in target organizations. The focus on large institutions across multiple sectors amplifies the potential payout while also creating significant reputational risk for victims.

Enhanced Description

Key Capabilities

  • Exfiltrating massive volumes of Salesforce data via authorized API queries
  • Stealing and abusing OAuth access tokens from Salesforce orgs using open‑source credential scanners (e.g., TruffleHog)
  • Leveraging compromised third‑party integrations (Salesloft Drift) to obtain tokens and expand reach
  • Deploying malicious Python scripts or custom extensions within Salesforce for persistence and exfiltration
  • Exploiting misconfigurations in Experience Cloud (Aura) and abuse of trial account permissions
  • Conducting voice‑based phishing (vishing) routed through VPN/Tor for initial access
  • Issuing ransomware‑style extortion demands linked to data exposure
  • Performing lateral movement inside victim environments with stolen credentials

MITRE ATT&CK Tactics

Credential Access
Initial Access
Reconaissance
Command and Control
Exfiltration
Impact

ATT&CK Techniques

T1036
T1041
T1059
T1078
T1078.001
T1078.002
T1083
T1090
T1112
T1189
T1213
T1585
T1586
T1587
T1587.001
T1588
T1588.002
T1595.003
T1598
T1608
T1608.005
T1684
T1684.001

Software / Tooling

AuraInspector
Data Loader
Hexstrike‑AI
Mullvad VPN
Okta phishing panel
Python script
Salesloft Drift
SolarWinds
TruffleHog
Tor

Campaigns & Victims

UNC6395 follows a multi‑stage, patient operational cadence that begins with supply‑chain compromise and token theft, followed by the deployment of malicious extensions or scripts within compromised Salesforce environments. The actor typically moves through three phases: first, credential collection via OAuth tokens; second, data discovery and bulk export using legitimate APIs; third, extortion messaging tied to potential leaks. Victim profiles skew toward large organizations with extensive Salesforce usage, but smaller institutions have also been observed. The group maintains operational opacity by deleting query jobs while leaving logs intact, thereby reducing forensic footprints yet preserving audit trails for analysis. Notable operations include an August 2025 incident that compromised 760 salesforce orgs and exfiltrated ~1.5 B records, a March 2026 attack on Experience Cloud using a custom AuraInspector scanner paired with a ransom demand, and repeated use of vishing over anonymized voice channels to coerce credential disclosure.

IOC Patterns

  • Unauthorized usage of OAuth tokens in Salesforce API calls
  • Large‑volume data export queries indicating exfiltration
  • Malicious user‑agent strings such as 'RapeForce'
  • Credential leakage from source‑code repositories detected by TruffleHog
  • Suspicious email addresses and domains used for phishing
  • IP addresses or networks associated with VPN/Tor proxies
  • CVE identifiers referenced in exploit campaigns
  • Malformed or hidden domain names linked to malicious sites

Recommended Actions

  • Enable multi‑factor authentication on all platform access, including OAuth token streams.
  • Rotate and invalidate compromised OAuth tokens promptly across all Salesforce orgs.
  • Audit and monitor Salesforce API usage for anomalous data transfer patterns and large‑volume export queries.
  • Restrict and review third‑party app integrations in Experience Cloud, removing unapproved or trial account entries.
  • Patch misconfigurations in Salesforce Experience Cloud (Aura) to prevent unauthorized access.
  • Require strict controls on OAuth token issuance and scope for all third‑party integrations.
  • Implement employee awareness training focused on vishing and voice‑based social engineering attacks.
  • Inspect and restrict the use of anonymous VPNs or Tor for outbound voice‑call communications within the organization.
  • Apply patches promptly for identified CVE vulnerabilities, e.g., CVE‑2025‑55177, CVE‑2025‑43300, CVE‑2025‑53690.

Suggested Tags

Data Exfiltration
OAuth Token Abuse
Salesforce Breach
Extortion
Social Engineering – Vishing
API Exploitation
Supply‑Chain Compromise
Credential Theft
Ransomware
VPN Anonymization
Unsecured Credentials
UNC6395

Confidence Assessment

The information base is reasonably high in confidence regarding the actor’s financial motivation, use of OAuth token theft, and exploitation of Salesforce environments, as corroborated by multiple independent reports and technical analysis. However, gaps remain around precise attribution dates, full toolchain details outside publicly documented open‑source tools, and a comprehensive understanding of the actor’s internal structure or funding model. Additional evidence would strengthen confidence in the overall threat profile.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.huntress.com — Cited by web research for: UNC6040
  2. attack.mitre.org — Cited by web research for: T1059
  3. research.checkpoint.com — Cited by web research for: AdWind
  4. www.trendmicro.com — Cited by web research for: Expand
  5. attack.mitre.org — Cited by web research for: vnd.openxmlformats-officedocument.spreadsheetml.sheet
  6. https://malpedia.caad.fkie.fraunhofer.de/actor/unc6395 — Cited by AI analysis.
  7. https://www.securityweek.com/security-firms-hit-by-salesforce-salesloft-drift-breach/ — Cited by AI analysis.
  8. https://www.symmetry-systems.com/blog/what-we-know-so-far-about — Cited by AI analysis.

Intel Summary

26

Techniques

37

Tools

0

Campaigns

8

IOCs

0

Observed Data

11

Tactics

Tags

Critical Infrastructure
APT
Cloud compromise
Credential Theft
Espionage
Data Exfiltration
OAuth Token Abuse
Salesforce Breach
Extortion
Social Engineering – Vishing
API Exploitation
Supply‑Chain Compromise
Ransomware
VPN Anonymization
Unsecured Credentials
UNC6395

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
France (FR)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.