UNC6395 is a threat actor known for credential harvesting from corporate Salesforce instances.
Analyst brief
UNC6395 is a threat actor primarily focused on credential harvesting. It systematically exports large volumes of data from corporate Salesforce instances to search for secrets. The actor targets sensitive credentials including AWS access keys (AKIA), passwords, and Snowflake tokens. Defenders should carefully review Salesforce query and export logs for evidence of unauthorized data access.
UNC6395
unknown
The actor systematically exported large volumes of data from numerous corporate Salesforce instances. GTIG assesses the primary intent of the threat actor is to harvest credentials. After the data was exfiltrated, the actor searched through the data to look for secrets that could be potentially used to compromise victim environments. GTIG observed UNC6395 targeting sensitive credentials such as Amazon Web Services (AWS) access keys (AKIA), passwords, and Snowflake-related access tokens. UNC6395 demonstrated operational security awareness by deleting query jobs, however logs were not impacted and organizations should still review relevant logs for evidence of data exposure.
The primary intent of UNC6395 is credential harvesting. It searches through large volumes of data exported from corporate Salesforce instances for sensitive information such as AWS access keys, passwords, and Snowflake tokens.
What should defenders do to detect UNC6395 activity?+
Defenders should carefully review Salesforce query and export logs for evidence of unauthorized data access.