← Back to Daily Briefing

Between mid-2025 and mid-2026, threat actor ShinyHunters (UNC604/UNC6395) targeted Salesforce and interconnected SaaS environments using an identity-centric attack chain. The group bypassed perimeter defenses by utilizing vishing and supply chain compromises to gain initial access, subsequently exploiting misconfigured guest permissions to authorize malicious OAuth applications. By securing long-lived OAuth tokens and manipulating trusted SaaS-to-SaaS integrations, the actors achieved persistent, high-privilege access to sensitive enterprise data. This campaign avoided CVE-based exploitation, focusing instead on the abuse of OAuth trust mechanisms to facilitate large-scale data exfiltration while evading traditional vulnerability scanners.

  • Incident Overview: Identity-Centric SaaS Targeting

    • Targeted Salesforce instances and various interconnected SaaS-based enterprise applications.
    • Operated with high stealth for approximately one year, spanning mid-2025 to mid-2026.
    • Represented a strategic shift from software vulnerability exploitation to the abuse of identity and trust mechanisms.
  • Attack Mechanics: Vector and Exploitation Chain

    • Initial access was facilitated via sophisticated voice phishing (vishing) or secondary supply chain compromises.
    • Exploited misconfigured guest access permissions to move laterally within the cloud environment.
    • Focused on the authorization of malicious OAuth applications rather than exploiting software flaws.
    • Manipulated trusted relationships between integrated SaaS platforms to bypass perimeter security.
  • Threat Actor Profile: ShinyHunters (UNC604/UNC6395)

    • Demonstrated high technical proficiency in bypassing traditional perimeter-based security controls.
    • Possessed advanced knowledge of SaaS architecture and OAuth permission structures.
    • Effectively utilized multiple aliases, including UNC604 and UNC6395, to conduct the campaign.
  • Impact and Persistence: Long-Term Data Exfiltration

    • Achieved unauthorized access to highly sensitive organizational data within Salesforce environments.
    • Established long-term persistence through the use of long-lived OAuth grants.
    • Minimized detection probability by avoiding the execution of traditional malware or known exploits.
  • Defensive Actions: Mitigating OAuth and Identity Risks

    • Implement rigorous auditing and monitoring of all OAuth application authorizations and permissions.
    • Enforce strict principle of least privilege (PoLP) regarding guest access and third-party SaaS integrations.
    • Deploy behavioral analytics to detect anomalous SaaS-to-SaaS communication and token usage patterns.
    • Strengthen organizational resilience against vishing through advanced social engineering awareness training.

Related posts

  1. techjacksolutions.com — ShinyHunters Conducts Year-Long OAuth Campaign Against Salesforce Environments Without Exploiting Any CVE
  2. rhisac.org — ShinyHunters Abusing OAuth to Compromise SaaS Apps
  3. En
  4. Mitiga
  5. Vorlon
  6. Varonis
  7. Guardz
  8. Salesforceben
  9. Microsoft
  10. Appomni

LINK COPIED TO CLIPBOARD