UNC6661 is a Google Threat Intelligence/Mandiant-tracked cybercrime cluster associated with ShinyHunters-branded, extortion-oriented intrusions. The cluster has been linked to initial access and cloud-data theft operations against organizations using identity providers and SaaS services. It commonly conducts targeted voice phishing, impersonating internal IT or help-desk personnel and directing employees to convincing victim-branded credential-harvesting portals purportedly used for MFA updates. The operators capture SSO credentials and MFA codes, enroll attacker-controlled MFA devices to retain access, pivot through SSO-connected services, and exfiltrate data available to compromised accounts. Observed collection activity includes extraction of personally identifiable information from Salesforce and exports from SharePoint, OneDrive, and DocuSign. UNC6661 has also used compromised email accounts for follow-on phishing and deleted messages or security notifications to conceal activity. Extortion following some UNC6661 compromises has been attributed to UNC6240, the cluster associated with the ShinyHunters identity. UNC6661 is tracked alongside, but distinguished from, UNC6671 and UNC6240 based on infrastructure and operational characteristics.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cluster associated in the report with ShinyHunters activity and focused on cloud-SaaS data collection and exfiltration.
Named activity cluster mentioned as part of the cluster evolution associated with the ShinyHunters profile, but no specific operational details are provided in the content.
A Google-tracked activity cluster associated with many of the more complex recent vishing attacks.
Initial-access and data-theft cluster in a broader campaign abusing vishing and SSO compromise; positioned as the entity that performs the initial compromise and exfiltration prior to extortion/leaks by ShinyHunters.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.