UNC6345 is a threat cluster tracked for targeting Salesforce customer environments through abuse of compromised OAuth tokens tied to the Salesloft Drift third-party integration. The activity is associated with large-scale data theft from numerous corporate Salesforce instances, with attackers using stolen machine-to-machine OAuth access to systematically export sensitive data and support subsequent extortion demands. The cluster is part of a broader 2025 wave of attacks against Salesforce ecosystems in which customer instances, rather than Salesforce’s core platform, were accessed through identity and application-layer compromise. UNC6345 is specifically linked to the compromise and misuse of OAuth tokens associated with Drift, enabling unauthorized access to connected Salesforce environments without relying on exploitation of a Salesforce software vulnerability. The actor’s observed tradecraft centers on token theft, abuse of trusted third-party integrations, and bulk data exfiltration from victim SaaS environments. Public reporting places this activity alongside related Salesforce-focused intrusion waves involving social engineering, phishing, vishing, and malicious connected-app authorization by other tracked clusters such as UNC6040, as well as broader overlap in reporting with criminal ecosystems including ShinyHunters, Scattered Spider, and The Com. High-confidence attribution for UNC6345 itself supports data theft and extortion-linked operations against enterprise victims.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.