Threat Actor Unknown origin
UNC6395
The actor systematically exported large volumes of data from numerous corporate Salesforce instances. GTIG assesses the primary intent of the threat actor is to harvest credentials. After the data was exfiltrated, the actor searched through the data to look for secrets that could be potentially used to compromise victim environments. GTIG observed UNC6395 targeting sensitive credentials such as Amazon Web Services (AWS) access keys (AKIA), passwords, and Snowflake-related access tokens. UNC6395 demonstrated operational security awareness by deleting query jobs, however logs were not impacted and organizations should still review relevant logs for evidence of data exposure.
Indicators of Compromise 1
MITRE ATT&CK TTPs 10
T1078 T1078.004 T1098 T1133 T1195.002 T1212 T1213 T1499 T1558 T1566.002
Valid Accounts
Defense Evasion
Cloud Accounts
Defense Evasion
Account Manipulation
Persistence
External Remote Services
Persistence
Compromise Software Supply Chain
Initial Access
Exploitation for Credential Access
Credential Access
Data from Information Repositories
Collection
Endpoint Denial of Service
Impact
Steal or Forge Kerberos Tickets
Credential Access
Spearphishing Link
Initial Access
Source Articles
Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity
Microsoft has identified three attack paths used by threat actors associated with ShinyHunters to compromise Salesforce environments over a year-long campaign from mid-2025 to mid-2026. The attackers exploited trusted OAuth integrations through vishing attacks, stole OAuth tokens from compromised third-party vendors like Drift, Gainsight, and Klue, and abused misconfigured guest access in Salesforce Experience Cloud sites. These methods allowed persistent access to CRM data without exploiting platform vulnerabilities, blending malicious activity with legitimate traffic. The campaigns targeted organizations across retail, education, and manufacturing sectors, leveraging social engineering, supply chain compromises, and poor identity governance.
hacker-news ·2w ago
The Replicant in Your Directory: AI Agents and the Identity Security Gap
The article discusses how AI agents and machine identities are outpacing traditional identity governance, creating a growing security gap. These non-human identities, such as service accounts and OAuth applications, often inherit excessive permissions and persist long after their original purpose, increasing the attack surface. A notable incident involved threat actor UNC6395 exploiting a trusted OAuth token from Salesloft's Drift integration to pivot across Salesforce, AWS, and Snowflake environments. The core issue is not new vulnerabilities, but the lack of ownership, visibility, and lifecycle management for machine identities.
bleeping-computer ·2w ago