Threat Actor Unknown origin
UNC6040
UNC6040 is a financially motivated threat cluster that employs vishing to gain access to organizations' Salesforce environments, facilitating large-scale data exfiltration. The group manipulates end users into authorizing malicious connected apps, often masquerading as IT support personnel, to exploit OAuth permissions. Following initial access, UNC6040 leverages harvested credentials to move laterally within victim networks, targeting other cloud platforms like Okta and Microsoft 365. Their operations are characterized by the use of Mullvad VPN IP addresses and a focus on social engineering tactics to bypass security measures.
Indicators of Compromise 1
MITRE ATT&CK TTPs 10
T1078 T1078.004 T1098 T1133 T1195.002 T1212 T1213 T1499 T1558 T1566.002
Valid Accounts
Defense Evasion
Cloud Accounts
Defense Evasion
Account Manipulation
Persistence
External Remote Services
Persistence
Compromise Software Supply Chain
Initial Access
Exploitation for Credential Access
Credential Access
Data from Information Repositories
Collection
Endpoint Denial of Service
Impact
Steal or Forge Kerberos Tickets
Credential Access
Spearphishing Link
Initial Access