Google warns UNC6395 stole data via Salesforce integrations

Spread the love
Google warns UNC6395 stole data via Salesforce integrations

A cyberattack exploiting a third-party application has resulted in data breaches across multiple Salesforce instances, according to Google’s Threat Intelligence Group. The attacks, attributed to a group tracked as UNC6395, leveraged compromised OAuth tokens associated with the Salesloft Drift application to exfiltrate sensitive data.

Google’s Threat Intelligence Group (GTIG) identified UNC6395 as the perpetrator of a “widespread data theft” campaign. This campaign, which commenced around August 8 and continued through at least August 18, targeted Salesforce instances by exploiting authentication tokens belonging to the Salesloft Drift application. This application, designed to automate sales processes, integrates with Salesforce databases for communication, analysis, and customer engagement purposes. The compromised tokens facilitated unauthorized access to sensitive information stored within the targeted systems.

The primary objective of UNC6395 was the systematic extraction of large volumes of data from numerous corporate Salesforce instances. GTIG researchers indicated that the actor’s intent was to harvest sensitive credentials, focusing on Amazon Web Services (AWS) access keys (AKIA), passwords, and Snowflake-related access tokens. Once extracted, this information could be leveraged to gain unauthorized access to various systems and services.

Following the exfiltration of data, UNC6395 conducted searches within the stolen information to identify secrets that could potentially be used to compromise victim environments. GTIG stated that the actor used specific queries to identify these credentials. To conceal their activities, the group subsequently deleted query jobs, attempting to erase evidence of the data theft. The removal of these logs made tracing the full extent of the breach more difficult, though GTIG has provided guidance for investigating potential data exposure.

GTIG issued recommendations for remediation and mitigation, emphasizing that the campaign’s impact appears to be limited to Salesloft customers who integrate their solutions with the Salesforce service. There is no evidence suggesting a direct impact on Google Cloud customers. However, GTIG advised that any customers utilizing Salesloft Drift should review their Salesforce objects for any Google Cloud Platform service account keys, as these may have been exposed during the data theft.

Given the nature of the attack, GTIG urged organizations using Drift integrated with Salesforce to consider their Salesforce data compromised and to take immediate remediation steps. These steps are designed to contain the breach and prevent further unauthorized access.

To address the situation, Salesloft collaborated with Salesforce to revoke all active access and refresh tokens associated with the Drift application. This action aimed to prevent ongoing unauthorized access through the compromised tokens. Additionally, Salesforce removed the Drift application from the Salesforce AppExchange pending further investigation, making it unavailable for new installations until the security concerns are resolved. GTIG, Salesforce, and Salesloft have notified organizations believed to be impacted by the data theft.

Prior to this incident, multiple high-profile companies, including Adidas, Pandora, Allianz, Tiffany & Co., Dior, Louis Vuitton, Workday, and Google, reported breaches via a third-party platform, which was reportedly Salesforce. The threat group ShinyHunters claimed responsibility for many of these attacks, with vishing attacks cited as the primary method of compromise. These earlier breaches underscored the vulnerability of systems relying on third-party integrations.

In June, Google reported that a financially motivated threat group, tracked as UNC6040, was impersonating IT support staff in vishing attacks to gain access to organizations’ Salesforce environments. Google stated that UNC6040 claimed to be ShinyHunters. Using these tactics, UNC6040 breached one of Google’s own Salesforce instances. The report highlighted the increasing sophistication of threat actors in targeting Salesforce environments using social engineering techniques.

While the timeline of these earlier Salesforce breaches overlaps with the UNC6395 Salesloft Drift activity, Google clarified that the methods of compromise are distinctly different. Google has stated that the UNC6395 Salesloft Drift activity is separate from the vishing attacks attributed to UNC6040. A GTIG spokesperson affirmed that there is no compelling evidence connecting the two campaigns, thus indicating that the breaches are independent events carried out by different threat actors.

In addition to the remediation steps already taken, Google recommended that impacted organizations search for sensitive information and secrets contained within Salesforce objects and take appropriate action. These actions include revoking API keys, rotating credentials, and conducting further investigations to determine if the secrets were abused by UNC6395. Organizations should also investigate for compromise and scan for exposed secrets, using indicators of compromise (IOCs) provided by GTIG, such as IP addresses and User-Agent strings identified in the Mandiant blog post. A broader search for activity originating from Tor exit nodes is also advised.

Further mitigation steps include reviewing Salesforce Event Monitoring logs for unusual activity associated with the Drift connection user, authentication activity from the Drift Connected App, and UniqueQuery events that log executed SOQL queries. Organizations can also open a Salesforce support case to obtain specific queries used by the threat actor and search Salesforce objects for potential secrets. Immediate revocation and rotation of discovered keys or secrets, resetting passwords, and configuring session timeout values in Session Settings to limit the lifespan of a compromised session are also recommended.

Google also advised organizations to harden access controls by ensuring that applications have the minimum necessary permissions, enforcing IP restrictions on the connected app, and defining login IP ranges to allow access only from trusted networks. These measures aim to reduce the attack surface and limit the potential impact of future compromises.


Featured image credit

FAQs

Frequently Asked Questions

What is a Premium Domain Name?   A premium domain name is the digital equivalent of prime real estate. It’s a short, catchy, and highly desirable web address that can significantly boost your brand's impact. These exclusive domains are already owned but available for purchase, offering you a shortcut to a powerful online presence. Why Choose a Premium Domain? Instant Brand Boost: Premium domains are like instant credibility boosters. They command attention, inspire trust, and make your business look established from day one. Memorable and Magnetic: Short, sweet, and unforgettable - these domains stick in people's minds. This means more visitors, better recall, and ultimately, more business. Outshine the Competition: In a crowded digital world, a premium domain is your secret weapon. Stand out, get noticed, and leave a lasting impression. Smart Investment: Premium domains often appreciate in value, just like a well-chosen piece of property. Own a piece of the digital world that could pay dividends. What Sets Premium Domains Apart?   Unlike ordinary domain names, premium domains are carefully crafted to be exceptional. They are shorter, more memorable, and often include valuable keywords. Plus, they often come with a built-in advantage: established online presence and search engine visibility. How Much Does a Premium Domain Cost?   The price tag for a premium domain depends on its desirability. While they cost more than standard domains, the investment can be game-changing. Think of it as an upfront cost for a long-term return. BrandBucket offers transparent pricing, so you know exactly what you're getting. Premium Domains: Worth the Investment?   Absolutely! A premium domain is more than just a website address; it's a strategic asset. By choosing the right premium domain, you're investing in your brand's future and setting yourself up for long-term success. What Are the Costs Associated with a Premium Domain?   While the initial purchase price of a premium domain is typically higher than a standard domain, the annual renewal fees are usually the same. Additionally, you may incur transfer fees if you decide to sell or move the domain to a different registrar. Can I Negotiate the Price of a Premium Domain? In some cases, it may be possible to negotiate the price of a premium domain. However, the success of negotiations depends on factors such as the domain's demand, the seller's willingness to negotiate, and the overall market conditions. At BrandBucket, we offer transparent, upfront pricing, but if you see a name that you like and wish to discuss price, please reach out to our sales team. How Do I Transfer a Premium Domain?   Transferring a premium domain involves a few steps, including unlocking the domain, obtaining an authorization code from the current registrar, and initiating the transfer with the new registrar. Many domain name marketplaces, including BrandBucket, offer assistance with the transfer process.