About this actor
UNC6040 is a financially motivated threat cluster that employs vishing to gain access to organizations' Salesforce environments, facilitating large-scale data exfiltration. The group manipulates end users into authorizing malicious connected apps, often masquerading as IT support personnel, to exploit OAuth permissions. Following initial access, UNC6040 leverages harvested credentials to move laterally within victim networks, targeting other cloud platforms like Okta and Microsoft 365. Their operations are characterized by the use of Mullvad VPN IP addresses and a focus on social engineering tactics to bypass security measures.
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MandiantUNC uncategorised cluster
How we know this
- Data origin
- MISP threat-actor galaxy Imported from the open-source MISP threat-actor galaxy.
- Techniques
- Curated — 5 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
CA-7 | 4 / 5 | 80% |
CM-6 | 4 / 5 | 80% |
SI-4 | 4 / 5 | 80% |
AC-2 | 3 / 5 | 60% |
AC-3 | 3 / 5 | 60% |
AC-5 | 3 / 5 | 60% |
AC-6 | 3 / 5 | 60% |
CM-5 | 3 / 5 | 60% |
CM-7 | 3 / 5 | 60% |
IA-2 | 3 / 5 | 60% |
IA-5 | 3 / 5 | 60% |
SC-28 | 3 / 5 | 60% |
SC-7 | 3 / 5 | 60% |
AC-20 | 2 / 5 | 40% |
AC-4 | 2 / 5 | 40% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- ShinyHunters 0.83
- scattered lapsus$ hunters 0.83
- BlackBasta 0.20
- Luna Moth 0.20
- PittyTiger 0.14