Skip to main content
Mallory
1 malware family

UNC6345

Also known asUNC6345

UNC6345 is a threat actor cluster identified by Mandiant/Google Threat Intelligence Group that targeted Salesforce customer instances through compromised OAuth tokens associated with Salesloft’s Drift third-party application. Reported activity in 2025 involved using exfiltrated Salesloft Drift OAuth credentials to systematically export large volumes of data from numerous corporate Salesforce instances. The broader incident set was associated with large-scale data theft and extortion affecting organizations’ Salesforce environments. The content directly attributes the Drift-token abuse to UNC6345. No additional confirmed aliases or sub-groups are provided beyond the lowercase/uppercase rendering of the same name.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.