UNC6395, also tracked by Cloudflare Cloudforce One as GRUB1, is a threat activity cluster associated with the 2025 Salesloft Drift supply-chain compromise and large-scale theft of data and credentials from connected enterprise SaaS environments. Google Threat Intelligence Group and Mandiant attributed the campaign to UNC6395. The activity reached hundreds of organizations, with more than 700 organizations identified as potentially impacted, including numerous cybersecurity and enterprise software providers and U.S.-based organizations. The intrusion involved access to Salesloft's GitHub environment beginning as early as March 2025, followed by access to Drift's AWS environment and theft of customer integration tokens. Between August 8 and at least August 18, 2025, UNC6395 abused compromised OAuth access and refresh tokens associated with Drift integrations to access downstream Salesforce environments without additional interactive authentication. The compromise also affected integrations beyond Salesforce, including Google Workspace. The actor enumerated Salesforce resources and issued high-volume API and SOQL queries to export account, contact, opportunity, user, and support-case records. It searched stolen data for passwords, AWS access keys, Snowflake authentication tokens, and other secrets that could enable further compromise, including through use of TruffleHog. UNC6395 exploited trusted integration identities rather than a Salesforce platform vulnerability. Its activity blended with legitimate integration traffic through valid tokens, common user agents, and standard API operations. The actor deleted Salesforce query jobs to hinder investigation and created at least one additional user account as a persistence mechanism.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
UNC6395 compromised OAuth tokens associated with Salesloft’s Drift integration and abused trusted connections to access downstream Salesforce environments. The August 2025 SaaS supply-chain breach involved stolen Salesforce data and reached hundreds of companies, including cybersecurity organizations. The content does not identify malware, exploited CVEs, attacker origin, or state sponsorship.
Conducted the Salesloft Drift compromise campaign, stealing Salesforce data and extracting tokens and secrets from support tickets; credentials exposed through this activity were used in the separate TELUS Digital intrusion attributed to ShinyHunters.
Used a compromised OAuth token tied to Salesloft's Drift chat integration to access Salesforce environments across hundreds of organizations and pivot to additional credentials and tokens, including AWS keys and Snowflake tokens.
Conducted a campaign in 2025 abusing a compromised OAuth token tied to Salesloft's Drift chat integration to move across Salesforce environments and obtain additional secrets including AWS credentials and Snowflake tokens.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.