Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-02

UNC6395

As of 2026-07-25, UNC6395 is a threat actor tracked by Threadlinqs Intelligence across 7 threats spanning threat intel, data breach, threat actor. ATT&CK coverage spans 93 techniques across 15 tactics in 7 of 7 tracked threats. Most-observed techniques: T1213 (Data from Information Repositories), T1528 (Steal Application Access Token), T1530 (Data from Cloud Storage).

Tracked threats
71 critical · 5 high · 1 medium
First seen
2026-02-02
Last seen
2026-07-25
ATT&CK techniques
93across 7 of 7 threats
Related CVEs
0None referenced
7 tracked threat(s) · Categories: THREAT_INTEL, DATA_BREACH, THREAT_ACTOR, CAMPAIGN

Activity timeline

UNC6395 appears in 7 tracked threats between and ; the busiest month was 2026-02 with 5 reports.

ATT&CK techniques observed

93 techniques observed across 7 of 7 tracked threats · Credential Access (15), Resource Development (12), Initial Access (11), Discovery (9), Stealth (formerly Defense Evasion) (9), Impact (7)
  • T1213 Data from Information Repositories — Collectionobserved in 6 of 7 tracked threats
  • T1528 Steal Application Access Token — Credential Accessobserved in 6 of 7 tracked threats
  • T1530 Data from Cloud Storage — Collectionobserved in 6 of 7 tracked threats
  • T1657 Financial Theft — Impactobserved in 6 of 7 tracked threats
  • T1078 Valid Accounts — Initial Accessobserved in 5 of 7 tracked threats
  • T1098 Account Manipulation — Persistenceobserved in 5 of 7 tracked threats
  • T1199 Trusted Relationship — Initial Accessobserved in 5 of 7 tracked threats
  • T1526 Cloud Service Discovery — Discoveryobserved in 5 of 7 tracked threats
  • T1537 Transfer Data to Cloud Account — Exfiltrationobserved in 5 of 7 tracked threats
  • T1550 Use Alternate Authentication Material — Lateral Movementobserved in 5 of 7 tracked threats
  • T1552 Unsecured Credentials — Credential Accessobserved in 5 of 7 tracked threats
  • T1566 Phishing — Initial Accessobserved in 5 of 7 tracked threats
  • T1566.004 Spearphishing Voice — Initial Accessobserved in 5 of 7 tracked threats
  • T1567 Exfiltration Over Web Service — Exfiltrationobserved in 5 of 7 tracked threats
  • T1583 Acquire Infrastructure — Resource Developmentobserved in 5 of 7 tracked threats

Tracked threats