UNC5537 is a financially motivated cybercrime cluster associated with the 2024 large-scale compromise of Snowflake customer accounts. The activity relied on valid customer credentials previously harvested by infostealer malware, particularly from accounts without multifactor authentication and without restrictive network allow-listing, rather than exploitation of a Snowflake vulnerability. The campaign affected at least 165 organizations and resulted in theft of large volumes of personal, financial, telecommunications, and business data, followed by extortion and sale or advertisement of stolen data on criminal forums. Publicly identified victims included organizations in telecommunications, financial services, retail, insurance, and consumer sectors. UNC5537 conducted Snowflake reconnaissance and querying through native Snowflake interfaces and command-line tooling, DBeaver Ultimate, and a utility tracked as FROSTBITE. Reporting has associated members with North America and Turkey, and identified alleged online pseudonyms including Judische and Waifu. Claims equating UNC5537 wholesale with Scattered Spider or ShinyHunters are not sufficiently established to treat those groups as confirmed aliases.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Separate activity cluster primarily attributed for the Snowflake customer-data theft campaign; mentioned to distinguish it from Scattered Spider.
Mentioned as background comparison in prior platform-level credential attacks against Snowflake customers.
Cybercrime group tied to a campaign that used stolen login credentials to access organizations' Snowflake data storage accounts, steal massive amounts of sensitive data, extort victims, and sell stolen data on hacking forums.
A financially motivated intrusion cluster tied to the 2024 Snowflake customer-account breaches, using credentials previously harvested by infostealer malware to access victim environments, steal data, and extort victims.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.