DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // SHINYHUNTERS-STORM3138FIRST SEEN: 2020

SHINYHUNTERS / STORM-3138

ALSO KNOWN AS: Storm-3138, UNC5537 (overlapping tradecraft)
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Unknown (English-speaking cybercriminal collective; international membership)
ATTRIBUTION:ORGANIZED CRIME
STATUS:ACTIVE
FIRST OBSERVED:2020
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL75/100
RESOURCES75/100
PERSISTENCE78/100
STEALTH70/100
IMPACT84/100

On July 13, 2026, Microsoft published a major research mapping a year-long ShinyHunters campaign (mid-2025 to mid-2026) targeting Salesforce environments across more than 700 organizations via three distinct attack paths: vishing attacks impersonating IT support to gain OAuth consent for malicious apps, supply chain compromise through trusted integrations (Salesloft Drift in Aug 2025, Gainsight in Nov 2025, Klue in Jun 2026), and abuse of misconfigured Salesforce guest-user Aura endpoints. Because all activity flows through legitimate OAuth tokens and approved application identities, it appears indistinguishable from routine Salesforce API usage, evading conventional sign-in detections. The Klue incident (June 2026) cascaded to expose data from Huntress and Recorded Future via downstream Salesforce and Gong integrations.

Data theft and extortion at scale; CRM and SaaS data aggregation for resale and ransom leverage; supply chain pivot attacks against SaaS vendor ecosystems

Voice phishing (vishing) impersonating IT support, OAuth consent abuse (malicious Salesforce Data Loader app), SaaS supply chain vendor compromise, OAuth token reuse across downstream tenants, Salesforce Aura guest endpoint scanning, CRM data enumeration and exfiltration via legitimate API calls, persistence through long-lived application tokens, MFA bypass via OAuth workflow abuse

RETAIL
EDUCATION
MANUFACTURING
TECHNOLOGY
SAAS VENDORS
CRM PLATFORMS

Malicious Salesforce connected apps masquerading as Data Loader, compromised Salesloft Drift/Gainsight/Klue vendor credentials, attacker-controlled Salesforce OAuth app registrations, DigitalOcean-hosted C2 infrastructure

FILE DATE: AUG 2025
Salesloft Drift Supply Chain OAuth Pivot
Compromised Salesloft Drift credentials exposed OAuth connection secrets, enabling cascading unauthorized access to multiple downstream customer Salesforce environments.
FILE DATE: NOV 2025
Gainsight SaaS Integration Abuse
Follow-on supply chain attack abusing Gainsight-published Salesforce apps, resulting in persistent █████████████████ 200+ affected Salesforce customer instances.
FILE DATE: JUN 2026
Klue / Storm-3138 CRM Data Exfiltration
Storm-3138 exploited legacy credentials at market-intelligence firm Klue to harvest OAuth tokens and exfiltrate Salesforce and Gong data impacting downstream clients including Huntress and Recorded Future.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn