logo

New Cybercrime Wave: UNC3944 Exploits SaaS Vulnerabilities

ID: f038f26e-27ad-5394-8b2b-21eb5c5b2550

STIX ID: report--f038f26e-27ad-5394-8b2b-21eb5c5b2550

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2024-06-17

Date Updated: 2026-04-22

Author: do son

...
...

Mandiant warns that UNC3944 (also tracked as 0ktapus/Octo Tempest/Scatter Swine) has evolved from credential harvesting and SIM swapping to targeted data theft and extortion of SaaS environments, employing social engineering, Okta permission abuse, VM compromise, and cloud synchronization tools for exfiltration; recommended mitigations include enhanced SaaS monitoring, richer logging, and stricter conditional access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.