RapeFlake is a custom data-exfiltration utility used in attacks against Snowflake customer environments. It is associated with the UNC5537 campaign that began in mid-April 2024, in which attackers accessed customer accounts using credentials previously stolen by infostealer malware. Compromised accounts commonly lacked multifactor authentication. Attackers used RapeFlake alongside Snowflake’s web interface and command-line tools to extract data.
The broader campaign affected organizations across multiple industries, including financial services, telecommunications, and entertainment, and involved extortion and the sale of stolen data on cybercrime forums. RapeFlake’s internal implementation and additional capabilities are not established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The threat actors ... used various methods, including the web-based UI, command-line tools, and a custom utility named "rapeflake" to exfiltrate data.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named data-theft tool referenced as having been used in the SnowFlake data theft attacks; mentioned only for naming similarity to the ShinyHunters tool.
An attack tool reportedly used in a Snowflake-focused credential-abuse campaign for data theft and extortion; specific capabilities are not described in the source.
Malware used to steal credentials, which were then used to access cloud accounts and exfiltrate sensitive data from organizations such as Ticketmaster and Advance Auto Parts.
Custom offensive utility used by UNC5537 to exfiltrate data from Snowflake customer accounts accessed with stolen credentials. The report attributes the broader campaign to infostealer-derived credentials and accounts lacking MFA, but does not identify the infostealer families involved.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.