Unc5537

Threat Actor updated 3 months ago (2024-11-29T13:57:48.201Z)
Download STIX
Preview STIX
UNC5537, a cyber threat actor group with members based in North America and Turkey, has been identified as a significant cybersecurity concern. Mandiant attributes the Snowflake compromises to UNC5537, which includes members such as John Erin Binns, an American man indicted by the U.S. Department of Justice for a 2021 breach at T-Mobile that exposed the personal information of over 76.6 million customers. The group's activities have primarily focused on hacking into telecommunications companies worldwide, with the group recognized as a distinct entity since May 2024. In April 2024, UNC5537 launched a systematic campaign compromising misconfigured SaaS instances across over a hundred organizations, leading to significant data loss and extortion attempts. The operation highlighted the potential harm an individual or group could inflict using readily available tools. Once customer accounts were compromised, UNC5537 executed similar SQL commands across multiple customer Snowflake instances to stage and exfiltrate data. The group was also assessed to have conducted reconnaissance against target Snowflake platforms. The group's activities escalated in 2024 when they made death threats against cybersecurity experts investigating their activities. In one instance, the group used artificial intelligence to create fake explicit photos of a researcher to harass them. Alexander ‘Connor’ Moucka, another member of UNC5537, was deemed one of the most consequential threat actors of 2024 by Mandiant. A joint investigation by Mandiant and Snowflake found that the majority of the credentials used by UNC5537 were available from historical infostealer infections dating back to 2020.
Description last updated: 2024-11-05T19:01:51.997Z
What's your take? (Question 1 of 2)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Snowflake
Cybercrime
Extortion
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Unc5537 Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more