HomeSecurityHackers target Salesforce accounts in extortion attacks

Hackers Target Salesforce Accounts in Extortion Attacks

Google has observed hackers claiming to belong to the ShinyHunters conducting social engineering attacks against multinational companies with the aim of stealing data from the organizations' Salesforce platforms.

See also: DollyWay World Domination attack hacked over 20,000 sites

Salesforce attacks

According to the Google Threat Intelligence Group (GTIG), which is tracking this threat cluster under the name “ UNC6040 ,” the attacks target English-speaking employees via voice phishing to trick them into connecting to a modified version of Salesforce’s Data Loader application

Attackers pretend to be support staff and ask the target employee to accept a connection to the Salesforce Data Loader application, a tool that allows users to import, export, update, or delete data in Salesforce environments.

The target organizations already use the cloud-based customer relationship management (CRM) platform Salesforce, which makes the malicious request to install the tool appear legitimate in the context of the attack.

In the UNC6040 group's attacks, the application is used to extract data stored in Salesforce environments and then laterally move it to connected platforms, such as Okta, Microsoft 365 , and Workplace.

See also: The North Face: Credential stuffing attacks allowed data breach

Access to these additional cloud platforms allows attackers to gain access to even more sensitive information, such as confidential communications, authorization tokens, documents, and more. In some cases, the data extraction process was prematurely interrupted as security systems detected unauthorized activity and suspended access. The attackers appear to have been aware of this risk and experimented with different packet sizes before escalating the attack.

Hackers Target Salesforce Accounts in Extortion Attacks
Hackers Target Salesforce Accounts in Extortion Attacks

The UNC6040 group also used modified versions of the Salesforce Data Loader application, giving them names that fit the social engineering context. For example, they renamed it “My Ticket Portal” and tricked victims into installing the application on their computers during a supposed support phone call.

For organizations using Salesforce, Google recommends restricting permissions with the “API Enabled” option, strictly controlling app installation authorization, and blocking access from commercial VPNs, such as Mullvad.

More information about protecting Salesforce from social engineering attacks is available here.

See also: BitM attacks – what they are and how to protect yourself

In Salesforce's case, because it is a highly prevalent cloud platform that manages vast amounts of sensitive business data, it is a frequent target of such attacks. For this reason, it is critical that organizations invest not only in technical protection measures (such as restricting API permissions or blocking VPNs), but also in training staff to recognize and avoid social engineering traps.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS