UNC6661 is a financially motivated cybercrime cluster tracked for sophisticated voice-phishing-led intrusions against enterprise identity and cloud SaaS environments. The cluster has been associated with extortion activity bearing the ShinyHunters branding and is tracked alongside related clusters including UNC6240 and UNC6671. Reporting distinguishes UNC6661 as primarily responsible for initial compromise and cloud data theft, while extortion in some intrusions has been attributed to UNC6240 under the ShinyHunters name. UNC6661’s tradecraft centers on social engineering rather than software exploitation. Operators impersonate internal IT or help-desk personnel in phone calls to employees, direct victims to company-branded credential-harvesting portals, and capture single sign-on credentials and multi-factor authentication codes in real time. After obtaining access, the cluster has been observed registering attacker-controlled MFA devices, abusing compromised identity accounts to pivot through centralized SSO portals, and moving into connected SaaS applications. Post-compromise activity includes theft of sensitive data and internal communications from cloud platforms, concealment actions such as deleting phishing emails sent from compromised accounts, and in some cases using compromised mailboxes to target additional organizations. The cluster’s operations have targeted identity providers and downstream SaaS ecosystems including Okta, Microsoft Entra ID, Google-linked environments, Salesforce, Microsoft 365, SharePoint, OneDrive, Slack, Atlassian, DocuSign, Dropbox, and Google Drive. Victimology includes cryptocurrency-focused companies, and the broader campaign has affected dozens of organizations. The activity is notable for bypassing some MFA deployments through user manipulation and enrollment abuse rather than malware or vendor vulnerabilities. UNC6661 is part of a broader ShinyHunters-linked extortion ecosystem characterized by SaaS-focused data theft, aggressive social engineering, and follow-on extortion pressure rather than endpoint ransomware deployment.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named activity cluster mentioned as part of the cluster evolution associated with the ShinyHunters profile, but no specific operational details are provided in the content.
A Google-tracked activity cluster associated with many of the more complex recent vishing attacks.
Initial-access and data-theft cluster in a broader campaign abusing vishing and SSO compromise; positioned as the entity that performs the initial compromise and exfiltration prior to extortion/leaks by ShinyHunters.
Mandiant-tracked cluster conducting vishing-led intrusions to obtain SSO credentials/MFA codes and access cloud/SaaS to steal data for extortion; distinguished by use of victim-branded domains for credential harvesting.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.