UNC5537 is a financially motivated cybercriminal group associated with a large-scale 2024 campaign against Snowflake customer environments. Its members have operated from Canada, the United States, and Turkey. Beginning in at least April 2024, the group compromised approximately 165 organizations, stole sensitive personal and financial records, demanded payment to prevent disclosure, and sold stolen data through cybercrime forums. Victims included AT&T, Ticketmaster, Santander Bank, Advance Auto Parts, Neiman Marcus, and Pure Storage. The campaign relied on valid customer credentials previously harvested by infostealer malware rather than exploitation of a Snowflake vulnerability. Compromised accounts lacked multifactor authentication, and access was facilitated by unrotated passwords and absent network allow-list restrictions. Some credentials remained valid despite having been exposed as early as November 2020. Infected employee and contractor devices supplied credentials, with compromised contractor systems potentially exposing access to multiple organizations. UNC5537 used SnowSight, the SnowSQL command-line interface, and DBeaver Ultimate to access databases and execute queries. Its custom utility FROSTBITE, also called rapeflake, supported SQL-based reconnaissance, including enumeration of users, roles, sessions, and organization information. The group extracted large datasets and monetized them through data sales and encryption-less extortion, including renewed disclosure threats against previously extorted victims. Connor Riley Moucka, associated with the handles Judische and Waifu, pleaded guilty to offenses arising from the campaign. Some stolen datasets were subsequently distributed under the ShinyHunters name; ShinyHunters and Scattered Spider are not established interchangeable aliases for UNC5537.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cited as a historical example in a credential-compromise guide. UNC5537 accessed approximately 165 organizations' Snowflake environments using previously stolen credentials. According to the content, missing MFA, unrotated credentials, and absent trusted-location restrictions enabled the campaign. An infected contractor laptop could expose credentials belonging to multiple organizations.
Separate activity cluster primarily attributed for the Snowflake customer-data theft campaign; mentioned to distinguish it from Scattered Spider.
Mentioned as background comparison in prior platform-level credential attacks against Snowflake customers.
Cybercrime group tied to a campaign that used stolen login credentials to access organizations' Snowflake data storage accounts, steal massive amounts of sensitive data, extort victims, and sell stolen data on hacking forums.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.