UNC6395UNC6395

Also known as: UNC6395

Known aliases
1

Profile

The actor systematically exported large volumes of data from numerous corporate Salesforce instances. GTIG assesses the primary intent of the threat actor is to harvest credentials. After the data was exfiltrated, the actor searched through the data to look for secrets that could be potentially used to compromise victim environments. GTIG observed UNC6395 targeting sensitive credentials such as Amazon Web Services (AWS) access keys (AKIA), passwords, and Snowflake-related access tokens. UNC6395 demonstrated operational security awareness by deleting query jobs, however logs were not impacted and organizations should still review relevant logs for evidence of data exposure.

Aliases· 1

UNC6395

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
UNC5537
Actor
UNC6426
Actor
UNC6040
Actor
UNC6671
Actor
UNC6353
Actor
UNC6293
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.