UNC6395 is a cybercriminal threat cluster tracked by Google Threat Intelligence Group and Mandiant for a 2025 supply-chain data-theft campaign against Salesforce environments. Cloudflare tracks the same activity as GRUB1. The cluster compromised OAuth and refresh tokens associated with Salesloft Drift, a third-party chat integration, then used the trusted application access to query and export data from hundreds of downstream Salesforce organizations. The activity also affected other authentication tokens stored in or connected to the Drift platform. UNC6395 used legitimate OAuth authorization and Salesforce API activity to access customer and business records, including Account, Contact, Case, User, and Opportunity data. It enumerated available data and API capabilities, conducted high-volume collection, and searched stolen records with secret-scanning tooling for credentials and access material, including cloud access keys, passwords, and Snowflake tokens. The cluster used bulk data-query functionality and deleted query jobs to impede investigation. It also created at least one new user account, consistent with an attempt to retain access after token revocation. The operation relied on abuse of trusted third-party identity relationships rather than exploitation of a Salesforce platform vulnerability. Its use of valid integration tokens and ordinary-looking API requests enabled access without interactive user authentication and reduced the effectiveness of conventional sign-in-focused detection. Public reporting has compared UNC6395 tradecraft with Salesforce-focused activity attributed to ShinyHunters and related clusters, but a definitive organizational relationship is not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted the Salesloft Drift compromise campaign, stealing Salesforce data and extracting tokens and secrets from support tickets; credentials exposed through this activity were used in the separate TELUS Digital intrusion attributed to ShinyHunters.
Used a compromised OAuth token tied to Salesloft's Drift chat integration to access Salesforce environments across hundreds of organizations and pivot to additional credentials and tokens, including AWS keys and Snowflake tokens.
Conducted a campaign in 2025 abusing a compromised OAuth token tied to Salesloft's Drift chat integration to move across Salesforce environments and obtain additional secrets including AWS credentials and Snowflake tokens.
Exploited a trusted OAuth token tied to Salesloft's Drift chat integration to access AWS credentials, Snowflake tokens, and other sensitive data across Salesforce environments, illustrating abuse of compromised machine identities rather than software vulnerabilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.