Also known as: Cisco, Chanel, Air France, tracked as, also known as ShinyHunters, UNC6240, ShinyHunters
UNC6040 operates as a sophisticated financially driven threat cluster that blends voice‑based social engineering (vishing) with cloud platform exploitation to achieve data exfiltration and extortion gains. Attackers impersonate trusted IT support personnel during phone calls, persuading employees to authorize counterfeit connected apps within Salesforce—most often a tampered version of Salesforce’s Data Loader. Once the application is approved, the actor harvests credentials and launches automated export scripts (custom Python or modified Data Loader) that rapidly offload vast amounts of data via web services such as the Salesforce API. The group then escalates privileges by leveraging compromised Okta and Microsoft 365 accounts; it also registers malicious SaaS applications using hijacked third‑party identities. To obfuscate their movements, UNC6040 frequently routes traffic through Mullvad VPN endpoints and occasionally exploits Tor exit nodes for command‑and‑control, complicating attribution and detection. Operationally, the threat actor has focused on multinational enterprises operating in highly regulated sectors—including financial services, government, energy, defense, aviation, healthcare, maritime, telecommunications, education, retail, and critical infrastructure. Their tactics show a rapid lifecycle: initial social engineering, credential theft, data exfiltration, lateral spread, and extortion demands typically delivered via email addresses such as shinycorp@tuta.com. While the overarching strategy remains financially motivated, the actor has shown adaptability by using native cloud services for persistence and moving through multiple platforms to maintain access and avoid detection.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNC6040, also known as ShinyHunters, is a financially‑motivated threat cluster that uses vishing and social engineering to force victims into authorizing malicious Salesforce connected applications. The group extracts large volumes of data from compromised Salesforce environments and later moves laterally through Okta and Microsoft 365 before demanding extortion payments via fake support emails. Their campaigns target high‑value sectors across France and the UK, leveraging VPN services for anonymity.
Goals & Targeting
UNC6040’s strategic objectives center on maximizing monetary gain through large‑scale data theft followed by extortion. By targeting high‑profile organizations in critical sectors across France and the UK, the actor seeks to leverage the value of proprietary or regulated information to compel victims into paying substantial demands. The use of cloud platforms such as Salesforce, Okta, and Microsoft 365 reflects a focus on environments where data is both easy to extract en masse and costly to remediate, thereby driving financial pressure. Additionally, the exploitation of voice‑based social engineering indicates an intent to bypass technical defenses via human manipulation, widening their attack surface.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UNC6040 campaigns exhibit a repeatable three‑phase pattern: (1) vishing outreach to coerce Salesforce approval of malicious connected apps; (2) rapid data extraction using automated scripts or the modified Data Loader, often within hours or days of initial compromise; and (3) lateral propagation to Okta and Microsoft 365 environments followed by extortion demands sent through spoofed support email addresses. The actor’s operational tempo is aggressive, delivering financial pressure before remediation can be fully applied. Victim profiles skew toward large multinational enterprises in regulated sectors where cloud adoption is high; recent operations have been documented mainly in France and the United Kingdom, but similar tactics are likely used elsewhere. Previous campaigns linked to a broader community of financially motivated actors—sometimes called “The Com” or “ShinyHunters”—suggest shared infrastructure such as Mopart VPN services and common phishing panels. While direct attribution remains uncertain, these inter‑actor linkages indicate potential collaboration or the use of overlapping toolsets for coordinated threat delivery. Notable past operations include a high‑profile breach of a European airline’s Salesforce data that resulted in a multi‑million euro extortion demand and an incident involving the exfiltration of confidential defense contractor records via a custom Data Loader build. These events underscore the actor’s capacity to scale attacks and execute swift exfiltration when leveraging cloud platforms. Overall, UNC6040 operates with operational sophistication, combining human manipulation with technical agility across several cloud ecosystems.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in the core attribution of vishing‐driven Salesforce exploitation and subsequent extortion is high, based on multiple independent reports. Confidence in the use of specific VPN services (Mullvad) and Tor for C2 is moderate; while mentioned frequently, direct evidence linking all operations is limited. Details regarding exact campaign timelines, full scope across sectors, and definitive proof of lateral movement into Microsoft 365 remain incomplete, indicating notable information gaps. Overall confidence is sufficient to inform defensive posture but should be corroborated with additional telemetry when possible.
No campaigns linked yet.
No observed data linked yet.
25
Techniques
34
Tools
0
Campaigns
40
IOCs
0
Observed Data
10
Tactics