Tuesday, September 15, 2026

Microsoft Uncovers Scattered Spider Tactics, Techniques, and Procedures in Recent Attacks

Microsoft has shed light on the sophisticated operations of Octo Tempest, a financially motivated cybercriminal group alternatively known as Scattered Spider, Muddled Libra, UNC3944, or 0ktapus.

This threat actor has demonstrated a versatile arsenal of tactics, techniques, and procedures (TTPs) in end-to-end attacks targeting organizations across various sectors.

Octo Tempest’s methodology typically begins with initial access through advanced social engineering campaigns, where attackers impersonate legitimate users to engage service desk support via phone calls, emails, or messages, often initiating password resets on targeted credentials.

This is frequently augmented by Short Message Service (SMS)-based phishing leveraging adversary-in-the-middle (AiTM) domains that mimic trusted organizations, enabling credential harvesting.

Once inside, the group employs tools like ngrok and Chisel for tunneling and persistence, alongside AADInternals for manipulating Azure Active Directory environments.

Their attacks often impact hybrid identity infrastructures, facilitating data exfiltration to support extortion or ransomware deployments.

Recent intrusions have shown a shift in focus, with Octo Tempest deploying DragonForce ransomware specifically against VMWare ESX hypervisor environments.

Scattered Spider
Attack path

Notably, unlike prior patterns relying on cloud identity privileges for on-premises pivots, current activities involve compromising on-premises accounts and infrastructure early on before escalating to cloud resources, highlighting an adaptive hybrid attack chain that blends reconnaissance, credential access, and lateral movement.

Automated Disruption Mechanisms

Microsoft Defender provides extensive detection capabilities across its security portfolio, encompassing endpoints, identities, SaaS applications, email tools, cloud workloads, and more, to counter Octo Tempest’s TTPs.

For initial access, detections include unusual user password resets in virtual machines via Microsoft Defender for Cloud (MDC).

Discovery phases are monitored through indicators like suspicious credential dumps from NTDS.dit in Microsoft Defender for Endpoint (MDE), account enumeration reconnaissance, network-mapping via DNS, and various Active Directory reconnaissance activities using LDAP and SAMR protocols in Microsoft Defender for Identity (MDI).

Credential access and lateral movement are flagged by detections for Mimikatz credential theft, ADExplorer usage, suspicious Azure role assignments, and DCSync attacks replicating directory services.

Persistence and execution are disrupted by identifying ADFS persistent backdoors, while defense evasion involves tampering activities typical of ransomware.

Actions on objectives, such as data staging and exfiltration over SMB, or DragonForce ransomware deployment, trigger preventions and hands-on-keyboard alerts in MDE.

To disrupt in-progress attacks, Microsoft Defender employs automatic attack disruption, an AI-powered self-defense mechanism that correlates multi-domain signals, threat intelligence, and machine learning models to predict and contain threats.

This includes disabling compromised user accounts and revoking active sessions based on indicators like Octo Tempest-related sign-ins, effectively severing attacker access. However, Microsoft emphasizes that security operations centers must follow up with incident response and post-incident analysis for full remediation.

Proactive Hunting

Organizations can leverage Microsoft Defender’s advanced hunting features to investigate Octo Tempest activities, querying across first- and third-party data sources in Microsoft Defender XDR and Microsoft Sentinel, supplemented by exposure insights from Microsoft Security Exposure Management.

This enables proactive assessment of potential targets, such as helpdesk-linked accounts, and simulation of attack paths to strengthen defenses pre-emptively.

For proactive defense, Microsoft Security Exposure Management offers tools like critical asset protection, where assets are classified to generate tailored attack paths and recommendations.

According to the Report, Initiatives such as the dedicated Octo Tempest Threat Initiative focus on mitigations like attack surface reduction (ASR) rules to block LSASS credential extraction via Mimikatz and conditional access policies for risky sign-ins from attacker-controlled IPs.

The broader Ransomware Initiative hardens identity, endpoint, and infrastructure layers against extortion tactics.

Attack path analysis traces hybrid threats, identifying chokepoints like Entra Connect servers exploited for privilege escalation and cloud pivots, allowing teams to prioritize remediation of vulnerable entities and minimize the impact of Octo Tempest’s aggressive social engineering and ransomware operations.

Get Free Ultimate SOC Requirements Checklist Before you build, buy, or switch your SOC for 2025 - Download Now

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor

China-linked threat actors tracked as UNC3569 have exploited a...

Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users

A Casbaneiro banking Trojan campaign targeting users across Latin...

AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process

A five-stage AsyncRAT campaign that chains a socially engineered...

Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data

Threat actors are increasingly using Claude-based AI workflows to...

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google...

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

A newly identified phishing campaign is abusing the legitimate...

Related Articles

Recent News