Suspicious Salesforce OAuth Refresh Token Use by Klue Battlecards App

PremiumReviewedSigma · Medium · v1
Product
salesforce
Author
HuntRule
Published
2026-09-15
Updated
2026-09-15

ATT&CK techniques

Initial Access → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Execution

  4. Defense Evasion

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects Salesforce API activity authenticated through an OAuth refresh token attributed to the Klue Battlecards connected application, the abused integration in this supply chain attack. The compromised app reused refresh tokens to authenticate as an external application and pull data without interactive login. Refresh token driven access from this connected app should be scrutinized for unauthorized data access.

Related detections9 linkedT1195.002 — drag to rearrange
Suspicious Salesforce Bulk Query by External App with Python-urllib Agent
Malicious axios NPM Supply Chain Persistence via MicrosoftUpdate Run Key
Malicious Registry Run Key Persistence Masquerading as MicrosoftUpdate
Suspicious Node.js Spawning Script Interpreter for Dropped Payload
Malicious Node.js Execution of Hidden .claude Setup Script
Malicious axios NPM Supply Chain C2 Domain Resolution
Suspicious Child Process Spawned by Python Interpreter via Process Creation
Suspicious npm Postinstall Node Execution From Fixtures Path (BeaverTail OtterCookie)
Suspicious TrueConf Update Chain Spawning Temporary Executable in Operation TrueChaos
Suspicious Salesforce OAuth Refresh Token Use by Klue Battlecards App
Pivot detection · T1195.002 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.