
criticalThreat Intelligence
UNC5537 Campaign Exploits Stolen Cloud Credentials in Massive Data Theft Targeting Snowflake Customers
Mandiant identifies UNC5537 as the threat actor behind a massive campaign targeting Snowflake customers, leveraging stolen credentials to exfiltrate petabytes of sensitive enterprise data.
22 July 2026Last updated 20 August 20265 min readMandiant
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- Cybercriminal
- Geography:
- Global
- Confidence:
- High Confidence
- Source:
- Mandiant
- Read Time:
- 5 min
Executive Summary\nAnalysis of recent cyber activity confirms a large-scale data exfiltration campaign orchestrated by the threat actor UNC5537. This campaign specifically targets organizations utilizing Snowflake’s cloud data platform. By leveraging credentials previously harvested through information-stealing malware, the actor has successfully bypassed perimeter defenses of numerous high-profile enterprises. There is currently no evidence suggesting a breach of Snowflake’s internal infrastructure; rather, the campaign exploits the lack of multi-factor authentication (MFA) on victim accounts and the persistence of historical credential leaks. The scope of the impact includes telecommunications, retail, and financial sectors, making it one of the most significant cloud-focused theft operations in recent years.\n\n## Threat Analysis\nUNC5537 is a financially motivated threat group that began its current operations in mid-2024, focusing on the systematic identification of Snowflake instances globally. The group employs a methodical approach, utilizing a custom reconnaissance tool to verify the validity of stolen credentials against Snowflake’s authentication endpoints. Once access is gained, the actor moves rapidly to stage and exfiltrate large volumes of data. The campaign is notable for its scale, with reports indicating over 165 organizations have been potentially impacted. The actor's primary objective appears to be pure extortion, threatening to leak sensitive data unless a ransom is paid, bypassing the need for traditional file-encrypting ransomware and focusing entirely on high-value data theft.\n\n## Technical Details\nThe attack sequence begins with the acquisition of credential sets from the 'logs' of info-stealer malware such as Redline, Vidar, and Raccoon, some of which date back to 2020. These credentials were used to access Snowflake customer accounts that were not protected by MFA. UNC5537 utilizes a custom utility referred to as 'FROSTBITE' to automate the discovery of databases and the extraction of metadata. To exfiltrate data, the actor uses legitimate database management tools and command-line interfaces to 'copy into' external cloud storage buckets (e.g., Amazon S3) controlled by the attacker. This technique often blends with legitimate administrative traffic, making detection difficult without granular logging and specialized cloud-threat detection rules.\n\n## Attribution Assessment\nIntelligence analysts from Mandiant and Google Cloud observe that UNC5537's operational patterns suggest a sophisticated cybercriminal entity. The group’s members are likely based in North America or Europe, given their proficiency in English and the timing of their communications on underground forums. While some technical overlaps with previous 'Lapsus$' or 'Scattered Spider' activity have been noted—particularly in their social engineering and credential-centric approach—UNC5537 is currently tracked as a distinct cluster of activity focused specifically on high-value cloud data warehouse environments. Their ability to manage large datasets indicates a high level of technical competency in cloud administration.\n\n## Implications\nThis campaign underscores a critical shift in the threat landscape where cloud-stored data is targeted directly without impacting underlying infrastructure. For enterprises, this represents a major reputational and legal risk, as seen in the recent massive data leaks affecting major telecommunications and retail giants. The reliance on stolen credentials highlights the 'identity' perimeter as the most vulnerable point in modern cloud architectures. Furthermore, the success of this campaign may inspire other threat actors to pivot away from traditional ransomware in favor of low-noise, high-impact data theft, which requires less infrastructure than maintaining encryption keys and decryption portals.\n\n## Recommendations\nEncrygma strongly recommends that all organizations utilizing cloud data platforms implement the following: 1. Enforce Multi-Factor Authentication (MFA) across all user accounts, specifically targeting service accounts and administrative consoles. 2. Implement Network Policy restrictions to allow access only from authorized IP addresses or VPN gateways. 3. Regularly rotate all credentials and audit for accounts using passwords that may have appeared in historical breaches. 4. Enable and monitor Snowflake 'Access History' and 'Query History' logs for unusual data volume transfers or unauthorized external stage creation. 5. Utilize session policies to limit the duration of active sessions and ensure least-privilege access is maintained for all cloud roles.
ENCRYGMA
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Share
Back to News RoomRelated Intelligence

Automated Ransomware Syndicate Deploys LLM-Powered Agent Framework Against Over 30 Enterprise Victims
05 Sep 2026

Krybit Ransomware Syndicate Escalates Global Campaign Targeting Critical Infrastructure and Legal Entities
01 Sep 2026

Threat Actors Pose as OpenAI, Anthropic and Google AI Crawlers to Harvest .env Files, AWS Keys and Private Certificates
02 Sep 2026
