UNC6395 is a cybercrime threat cluster publicly associated with large-scale data theft from Salesforce-connected environments through abuse of trusted third-party OAuth integrations rather than exploitation of a Salesforce software vulnerability. The cluster is also tracked as GRUB1 by Cloudflare. Activity attributed to UNC6395 became prominent in August 2025, when the actor used compromised OAuth and refresh tokens tied to Salesloft Drift integrations to access downstream Salesforce environments across hundreds of organizations. Reporting indicates the actor issued high volumes of Salesforce API requests, enumerated available objects, queried records such as Accounts, Contacts, Cases, Users, Opportunities, and related business data, and exported large volumes of information for follow-on credential harvesting and broader compromise. UNC6395’s tradecraft centers on abusing legitimate machine identities and trusted application access. The actor leveraged valid OAuth tokens to blend into normal SaaS activity, bypass traditional authentication controls, and reduce the likelihood of detection. Observed behavior includes reconnaissance within Salesforce APIs, bulk data extraction, searching stolen CRM data for embedded secrets such as cloud access keys, passwords, and Snowflake-related credentials, and deletion of query jobs to hinder investigation. Use of an open-source secrets scanning tool has also been reported. In at least one case, the actor created a new user account, indicating an effort to maintain persistence beyond token revocation. The cluster appears primarily financially motivated, with operations focused on theft of sensitive business data and credentials that can support extortion, resale, or follow-on intrusion. Confirmed targeting spans a broad set of organizations using Salesforce with third-party integrations, including major technology and security firms, and at least some activity affected U.S.-based organizations. High-confidence reporting also indicates that the compromise scope was not limited to Salesforce alone and that other authentication tokens stored in or connected to the affected integration platform may have been exposed. UNC6395 is frequently discussed alongside other Salesforce-focused cybercrime clusters such as ShinyHunters and UNC6040 because of overlapping victimology and tradecraft, but it is tracked as a distinct cluster.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used a compromised OAuth token tied to Salesloft's Drift chat integration to access Salesforce environments across hundreds of organizations and pivot to additional credentials and tokens, including AWS keys and Snowflake tokens.
Conducted a campaign in 2025 abusing a compromised OAuth token tied to Salesloft's Drift chat integration to move across Salesforce environments and obtain additional secrets including AWS credentials and Snowflake tokens.
Exploited a trusted OAuth token tied to Salesloft's Drift chat integration to access AWS credentials, Snowflake tokens, and other sensitive data across Salesforce environments, illustrating abuse of compromised machine identities rather than software vulnerabilities.
Cluster associated with the Salesloft Drift compromise in which stolen OAuth and refresh tokens from a trusted vendor integration were used to access many downstream Salesforce customer environments.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.