Uptime Hamster: 11d 12h 49mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza UNC6040

UNC6040

0 incidentes 0 paises 0 sectores apt Unknown Ultimo: -
Ver en IntelTracker → APTTrail →
UNC6040 is a financially motivated threat cluster first documented in October 2024, specializing in voice phishing (vishing) campaigns. This group distinguishes itself by primarily targeting organizations' Salesforce instances for large-scale data theft and subsequent extortion, relying on manipulating human behavior rather than exploiting software vulnerabilities. UNC6040 often operates in conjunction with or under the brand of ShinyHunters, with an associated group, UNC6240, frequently handling the extortion phase.
Tecnicas MITRE
T1021.002, T1059 - Command and Scripting Interpreter, T1534 - Internal Spearphishing, T1585 - Establish Accounts, T1539 - Steal Web Session Cookie, T1583.001 - Domains
CVEs relacionadas
CVE-2026-2441, CVE-2026-1340, CVE-2026-1281, CVE-2025-8088, CVE-2025-23297, CVE-2025-11371
Tipo
apt
Pais origen
Unknown
Motivacion
-
Impacto
54
Actualizado
Mon, 15 Se

Sectores objetivo (SOCRadar)

Rail TransportationHospitalsAccommodationAir TransportationConstructionPublic AdministrationEducational ServicesInternet PublishingInsuranceMotor Vehicle Manufacturing