← Threat Actors / Global / UNC6395
DOSSIER // UNC6395

UNC6395

▲ High Threat
Primary Aliases: No secondary vendor aliases recorded.
Sponsor / State Affiliation Independent / Not Attributed
Primary Motivation Espionage / Financial
Active Timeline Unknown – Present
Confidence Rating 70% (Grounded)

The actor systematically exported large volumes of data from numerous corporate Salesforce instances. GTIG assesses the primary intent of the threat actor is to harvest credentials. After the data was exfiltrated, the actor searched through the data to look for secrets that could be potentially used to compromise victim environments. GTIG observed UNC6395 targeting sensitive credentials such as Amazon Web Services (AWS) access keys (AKIA), passwords, and Snowflake-related access tokens. UNC6395 demonstrated operational security awareness by deleting query jobs, however logs were not impacted and organizations should still review relevant logs for evidence of data exposure.

⚔️ Weaponized CVE Matrix (0)

No specific weaponized CVEs currently mapped in the public baseline.

🎯 Target Sectors & Focus

Defense & Aerospace Government & Diplomacy Financial & Crypto Critical Infrastructure

🛡️ MITRE ATT&CK® Attack Lifecycle (0 TTPs)

📥 Download Navigator JSON
No tactical TTP mapping records recorded in database.

📰 Verified Campaigns & Intelligence Archive

🔔 Subscribe to Alerts
No recent breaking campaign alerts recorded in the FlagThis threat database.
Copied to clipboard

LINK COPIED TO CLIPBOARD