Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC6040

Also known as: Cisco, Chanel, Air France, tracked as, also known as ShinyHunters, UNC6240, ShinyHunters

Description

UNC6040 operates as a sophisticated financially driven threat cluster that blends voice‑based social engineering (vishing) with cloud platform exploitation to achieve data exfiltration and extortion gains. Attackers impersonate trusted IT support personnel during phone calls, persuading employees to authorize counterfeit connected apps within Salesforce—most often a tampered version of Salesforce’s Data Loader. Once the application is approved, the actor harvests credentials and launches automated export scripts (custom Python or modified Data Loader) that rapidly offload vast amounts of data via web services such as the Salesforce API. The group then escalates privileges by leveraging compromised Okta and Microsoft 365 accounts; it also registers malicious SaaS applications using hijacked third‑party identities. To obfuscate their movements, UNC6040 frequently routes traffic through Mullvad VPN endpoints and occasionally exploits Tor exit nodes for command‑and‑control, complicating attribution and detection. Operationally, the threat actor has focused on multinational enterprises operating in highly regulated sectors—including financial services, government, energy, defense, aviation, healthcare, maritime, telecommunications, education, retail, and critical infrastructure. Their tactics show a rapid lifecycle: initial social engineering, credential theft, data exfiltration, lateral spread, and extortion demands typically delivered via email addresses such as shinycorp@tuta.com. While the overarching strategy remains financially motivated, the actor has shown adaptability by using native cloud services for persistence and moving through multiple platforms to maintain access and avoid detection.

Goals & Targeting

Targeted Sectors

Financial services
Government
Energy
Defense
Aviation
Healthcare
Maritime
Telecommunications
Education
Retail
Critical infrastructure

Targeted Countries / Regions

FR
GB

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 14 hours ago

Executive Summary

UNC6040, also known as ShinyHunters, is a financially‑motivated threat cluster that uses vishing and social engineering to force victims into authorizing malicious Salesforce connected applications. The group extracts large volumes of data from compromised Salesforce environments and later moves laterally through Okta and Microsoft 365 before demanding extortion payments via fake support emails. Their campaigns target high‑value sectors across France and the UK, leveraging VPN services for anonymity.

Goals & Targeting

UNC6040’s strategic objectives center on maximizing monetary gain through large‑scale data theft followed by extortion. By targeting high‑profile organizations in critical sectors across France and the UK, the actor seeks to leverage the value of proprietary or regulated information to compel victims into paying substantial demands. The use of cloud platforms such as Salesforce, Okta, and Microsoft 365 reflects a focus on environments where data is both easy to extract en masse and costly to remediate, thereby driving financial pressure. Additionally, the exploitation of voice‑based social engineering indicates an intent to bypass technical defenses via human manipulation, widening their attack surface.

Enhanced Description

Key Capabilities

  • Vishing (voice phishing) social engineering
  • Impersonating IT support personnel
  • Deceptive authorization of malicious Salesforce connected apps (modified Data Loader)
  • Use of Mullvad VPN IPs for anonymizing voice traffic and exfiltration
  • Leveraging Okta phishing panel to phish credentials
  • Credential harvesting & MFA bypass
  • Lateral movement through compromised Okta/Microsoft 365 accounts
  • Exfiltration via Salesforce Data Loader or custom Python scripts
  • Using Tor browser for C2 anonymity

MITRE ATT&CK Tactics

Initial Access
Execution
Defense Evasion
Exfiltration
Credential Access
Lateral Movement

ATT&CK Techniques

T1036
T1059
T1069
T1078
T1083
T1090
T1204
T1566
T1566.004
T1567
T1585
T1586
T1587
T1588
T1593
T1598
T1608
T1608.005
T1671
T1684
T1684.001

Software / Tooling

Salesforce Data Loader (modified)
Okta phishing panel
Mullvad VPN service
Custom Python script
Tor browser

Campaigns & Victims

UNC6040 campaigns exhibit a repeatable three‑phase pattern: (1) vishing outreach to coerce Salesforce approval of malicious connected apps; (2) rapid data extraction using automated scripts or the modified Data Loader, often within hours or days of initial compromise; and (3) lateral propagation to Okta and Microsoft 365 environments followed by extortion demands sent through spoofed support email addresses. The actor’s operational tempo is aggressive, delivering financial pressure before remediation can be fully applied. Victim profiles skew toward large multinational enterprises in regulated sectors where cloud adoption is high; recent operations have been documented mainly in France and the United Kingdom, but similar tactics are likely used elsewhere. Previous campaigns linked to a broader community of financially motivated actors—sometimes called “The Com” or “ShinyHunters”—suggest shared infrastructure such as Mopart VPN services and common phishing panels. While direct attribution remains uncertain, these inter‑actor linkages indicate potential collaboration or the use of overlapping toolsets for coordinated threat delivery. Notable past operations include a high‑profile breach of a European airline’s Salesforce data that resulted in a multi‑million euro extortion demand and an incident involving the exfiltration of confidential defense contractor records via a custom Data Loader build. These events underscore the actor’s capacity to scale attacks and execute swift exfiltration when leveraging cloud platforms. Overall, UNC6040 operates with operational sophistication, combining human manipulation with technical agility across several cloud ecosystems.

IOC Patterns

  • Malicious Salesforce connected app approvals
  • Modified Data Loader usage for data export
  • Okta phishing portal accessed via mobile or work computers during calls
  • Mullvad VPN IP addresses used to proxy voice calls and exfiltration
  • Extortion demand emails from shinycorp@tuta.com & shinygroup@tuta.com
  • Use of Tor browser for command‑and‑control
  • Compromised third‑party accounts registered as malicious applications

Recommended Actions

  • Block authorization of unknown connected applications in Salesforce environments
  • Provide user education on vishing attacks and verification protocols for IT support calls
  • Audit Salesforce connected app approvals regularly
  • Monitor and restrict Okta application access from untrusted devices
  • Detect and block use of VPN services (e.g., Mullvad) for suspicious voice call traffic
  • Implement email filtering to detect and quarantine extortion demand messages
  • Validate all Salesforce connected apps and restrict creation to authorized users
  • Require multi‑factor authentication for Okta, Microsoft 365, and other cloud credentials
  • Monitor for anomalous data export activity through Data Loader or custom scripts
  • Block or monitor known VPN and Tor exit nodes used by the threat actor
  • Use network segmentation to limit lateral movement between cloud accounts
  • Train employees on recognizing vishing/voice phishing calls and social engineering tactics

Suggested Tags

SpearPhishingVoice
SalesforceDataLoaderAbuse
MullvadVPNProxy
OktaPhishingPanel
ExtortionDemand
DataExfiltration
SocialEngineering
financial-motivated
vishing
salesforce-exploitation
malicious-connected-apps
okta-credentials-theft

Confidence Assessment

The confidence in the core attribution of vishing‐driven Salesforce exploitation and subsequent extortion is high, based on multiple independent reports. Confidence in the use of specific VPN services (Mullvad) and Tor for C2 is moderate; while mentioned frequently, direct evidence linking all operations is limited. Details regarding exact campaign timelines, full scope across sectors, and definitive proof of lateral movement into Microsoft 365 remain incomplete, indicating notable information gaps. Overall confidence is sufficient to inform defensive posture but should be corroborated with additional telemetry when possible.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 20

References

  1. www.huntress.com — Cited by web research for: UNC6240
  2. attack.mitre.org — Cited by web research for: T1059
  3. cloud.google.com — Cited by web research for: PHOTO
  4. cloud.google.com — Cited by web research for: Phishing infrastructure
  5. attack.mitre.org — Cited by web research for: vnd.openxmlformats-officedocument.spreadsheetml.sheet

Intel Summary

25

Techniques

34

Tools

0

Campaigns

40

IOCs

0

Observed Data

10

Tactics

Tags

Critical Infrastructure
Phishing
Data Exfiltration
APT
Financially Motivated
Cloud Infrastructure
Social Engineering
Vishing
SpearPhishingVoice
SalesforceDataLoaderAbuse
MullvadVPNProxy
OktaPhishingPanel
ExtortionDemand
DataExfiltration
SocialEngineering
financial-motivated
vishing
salesforce-exploitation
malicious-connected-apps
okta-credentials-theft

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
France (FR)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.