UNC5537 is a financially motivated cybercrime cluster associated with the 2024 large-scale compromises of Snowflake customer environments. The activity has been linked in reporting and industry tracking to the broader ShinyHunters and Scattered Spider ecosystem, and some reporting also describes overlap with LAPSUS$-adjacent actors. Known aliases and handles associated with the cluster include ShinyHunters, Scattered Spider, Judische, and Waifu, although the exact organizational boundaries between these labels are not always consistent across public reporting. UNC5537 is best known for using previously stolen credentials, especially credentials harvested by infostealer malware, to access victim cloud data environments rather than exploiting a vulnerability in Snowflake itself. Investigations tied the compromises to exposed customer credentials, absent or unenforced multi-factor authentication, and lack of network allow-listing. Public reporting states that at least 165 organizations were affected. Victims publicly associated with the campaign span telecommunications, financial services, retail, software and technology, education, and other enterprise sectors. The actor’s tradecraft centers on credential-based initial access and cloud-native post-compromise activity. UNC5537 used valid accounts to log into Snowflake customer tenants through native interfaces and common database tooling, then conducted reconnaissance, queried datasets, and exfiltrated large volumes of records. Reporting also links the cluster to use of a custom Snowflake-focused utility tracked as FROSTBITE for SQL-based reconnaissance and bulk collection, as well as use of legitimate database management tools. The campaign is widely characterized as operationally effective but not dependent on novel exploitation, instead succeeding through identity compromise, weak authentication hygiene, and abuse of legitimate access paths. After data theft, UNC5537 extorted victims and in some cases advertised or distributed stolen data through cybercrime channels. Court reporting tied the campaign to ransom and data-sale proceeds and described re-extortion behavior against at least one victim. The actor is therefore associated with data-theft extortion rather than ransomware encryption operations. Public attribution and court proceedings have linked members of the cluster to North America and Turkey, including a Canadian defendant who pleaded guilty to charges related to the Snowflake intrusions and a co-defendant reported to be outside U.S. custody. Overall, UNC5537 is assessed as a financially motivated intrusion and extortion actor specializing in identity-driven access to cloud and SaaS environments, with strong overlap with prominent English-speaking cybercrime communities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A financially motivated intrusion cluster tied to the 2024 Snowflake customer-account breaches, using credentials previously harvested by infostealer malware to access victim environments, steal data, and extort victims.
Used infostealer-harvested credentials to access Snowflake customer environments and conduct large-scale data theft and extortion, relying on stolen usernames, passwords, and absent MFA rather than exploiting a software vulnerability.
Named activity cluster mentioned as part of the cluster evolution associated with the ShinyHunters profile, but no specific operational details are provided in the content.
Financially motivated threat group attributed with the Snowflake campaign, using stolen credentials obtained via infostealer malware to access Snowflake customer tenants, exfiltrate data, and extort victims.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.