UNC6671UNC6671

Also known as: UNC6671

Known aliases
1

Profile

UNC6671 is involved in credential harvesting operations, utilizing vishing tactics to impersonate IT staff and directing victims to enter credentials on a victim-branded site. They have gained access to Okta customer accounts and employed PowerShell to download sensitive data from SharePoint and OneDrive. Their extortion tactics include aggressive harassment of victim personnel, and they have used unbranded extortion emails with different Tox IDs for communication. The threat actors have shown a preference for registering domains with Tucows, indicating potential operational differences from related threat groups.

Aliases· 1

UNC6671

References

  1. https://cloud.google.com/blog/topics/threat-intelligence/expansion-shinyhunters-saas-data-theft/

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
UNC6691
Actor
UNC6040
Actor
UNC6692
Actor
UNC5537
Actor
UNC6395
Actor
UNC2465
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.