← Threat Actors / Global / UNC5537
DOSSIER // UNC5537

UNC5537

▲ High Threat
Primary Aliases: DEV-0971 Octo Tempest Scattered Spider UNC3944
Sponsor / State Affiliation Independent / Not Attributed
Primary Motivation Espionage / Financial
Active Timeline Unknown – Present
Confidence Rating 70% (Grounded)

UNC5537 is a financially motivated threat actor targeting Snowflake customer databases. They use stolen credentials obtained from infostealer malware to access and exfiltrate large volumes of data. The compromised accounts lack multi-factor authentication, allowing UNC5537 to conduct data theft and extortion.

⚔️ Weaponized CVE Matrix (1)

🎯 Target Sectors & Focus

Defense & Aerospace Government & Diplomacy Financial & Crypto Critical Infrastructure

🛡️ MITRE ATT&CK® Attack Lifecycle (8 TTPs)

📥 Download Navigator JSON

📰 Verified Campaigns & Intelligence Archive

🔔 Subscribe to Alerts
No recent breaking campaign alerts recorded in the FlagThis threat database.
Copied to clipboard

LINK COPIED TO CLIPBOARD