GRUB1 is a threat actor tracked by Cloudflare and aligned with Google’s UNC6395 cluster. The group is associated with a large-scale supply-chain and OAuth token theft campaign centered on the Salesloft-owned Drift integration with Salesforce. In this activity, the actor obtained access to Salesloft and Drift environments, including Drift’s cloud environment, stole OAuth tokens tied to customer technology integrations, and then used those tokens to access numerous victim Salesforce tenants. Publicly identified victims span a broad set of enterprise technology and security companies, and the incident affected hundreds of organizations. Observed GRUB1 activity includes reconnaissance in upstream provider environments, theft and abuse of OAuth credentials and tokens for initial access into downstream customer tenants, unauthorized access to Salesforce CRM data, and exfiltration of customer support case information, business contact records, and related sales or operational metadata. Reporting also indicates the actor accessed a Salesloft GitHub account over an extended period, downloaded repository content, added a guest user, and established workflows, indicating persistence and post-compromise operational activity in the supplier environment before downstream exploitation. The actor’s known operations in this cluster were largely confined to Salesforce-related environments at victim organizations rather than core production systems, internal networks, or customer platforms. Public reporting does not support ransomware deployment, destructive activity, or overt extortion in this campaign. The dominant pattern is theft of enterprise data through compromised third-party integrations and token abuse. Attribution beyond the GRUB1 and UNC6395 designations remains limited in the available information, and no high-confidence country of origin is established here.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cloudflare's designation for the threat group aligned with UNC6395 and linked to the Salesloft/Drift intrusion campaign affecting numerous companies via stolen OAuth tokens.
Attributed supply-chain attack activity against the Drift marketing SaaS product, involving mass theft of OAuth/authentication tokens and subsequent access to downstream customer data (e.g., Salesforce).
Named threat actor associated (in this reporting) with the Salesloft/Drift OAuth token compromise campaign, leveraging compromised Drift OAuth access to enter Salesforce tenants and exfiltrate customer support-case data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.