Monday, December 23, 2024
HomeCyber AttackScattered Spider: Advanced Techniques for Launching High-Profile Attacks

Scattered Spider: Advanced Techniques for Launching High-Profile Attacks

Published on

SIEM as a Service

Scattered Spider is a threat group responsible for attacking several organizations since May 2022 by using techniques like social engineering, ransomware, extortion, SIM Swapping and many other tactics.

There were also reports that this threat group was affiliated with the BlackCat ransomware since mid-2023.

Their most notable attacks that made it to the media include the compromise of Twilio in August 2022, Caesars Entertainment, and MGM Resorts in 2023.

- Advertisement - SIEM as a Service

However, this threat group has been constantly evolving with tactics, techniques, and procedures for their operations.

Scattered Spider Attack

According to the reports shared with Cyber Security News, Scattered Spider’s activities overlap with other intrusion set activities like 0ktapus, Scatter Swine, UNC3944, Octo Tempest, Muddled Libra, and many others.

The threat group is reported to consist of 17- to 22-year-old native English-speaking individuals who reside in Western countries.

Document
Live Account Takeover Attack Simulation

How do Hackers Bypass 2FA?

Live attack simulation Webinar demonstrates various ways in which account takeover can happen and practices to protect your websites and APIs against ATO attacks.

Between March and July 2022, this threat group compromised over 130 unique organizations in several industries, including technology, telecommunications, and cryptocurrency. 

Targeted Industries (Source: Sekoia)

Reports from Microsoft stated that this threat group also used personal information like residential addresses or relative names to threaten their victims into giving corporate credentials.

Once they gain access to the corporate networks, they perform a review of internal documents to collect details about the processes and procedures.

Later, they use this information to expand their scope and access sensitive systems and data.

In an advanced attack scenario, the threat group is using double-extortion tactics by deploying the BlackCat ransomware into the victim’s environment.

From Initial Access Broken To Ransomware Affiliate

During their early stages in 2022, Scattered Spider activities were associated with using intrusion sets to gain initial access to the organization’s accounts via social engineering.

Once they gather initial access information and other credentials, they sell it to other criminals for money. 

Timeline of Scattered Spider (Source: Sekoia)

In mid-2023, Scattered Spider joined BlackCat ransomware operations and began to deploy ransomware payloads on Windows and Linux systems.

Further, they evolved into performing data exfiltration, extortion, and other attacking methods. 

In late 2023, the threat group expanded its targets to Manufacturing, Hospitality, Law, Gaming, Natural resources, Financial services, and many others.

As of February 2024, the victims of Scattered Spider includes,

  • True Corporation
  • Zendesk
  • Squarespace
  • Walmart
  • Linkedin
  • Costco
  • Cellular Sales
  • Grubhub
  • Samsung
  • Gitlab
  • Fireblocks
  • Sinch
  • Roblox
  • Us Cellular
  • Apple
  • Binance
  • Verizon
  • Aflac
  • Bell
  • Allstate
  • Athene

Indicators Of Compromise

Phishing Domains

Phishing Servers

You can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits, with Perimeter81 malware protection. All are extremely harmful, can wreak havoc, and damage your network.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.

Eswar
Eswar
Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Latest articles

Skuld Malware Using Weaponized Windows Utilities Packages To Deliver Malware

Researchers discovered a malware campaign targeting the npm ecosystem, distributing the Skuld info stealer...

BellaCiao, A new .NET Malware With Advanced Sophisticated Techniques

An investigation revealed an intrusion in Asia involving the BellaCiao .NET malware, as the...

Malicious Apps On Amazon Appstore Records Screen And Interecpt OTP Verifications

A seemingly benign health app, "BMI CalculationVsn," was found on the Amazon App Store,...

Lazarus Hackers Using New VNC Based Malware To Attack Organizations Worldwide

The Lazarus Group has recently employed a sophisticated attack, dubbed "Operation DreamJob," to target...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

Skuld Malware Using Weaponized Windows Utilities Packages To Deliver Malware

Researchers discovered a malware campaign targeting the npm ecosystem, distributing the Skuld info stealer...

BellaCiao, A new .NET Malware With Advanced Sophisticated Techniques

An investigation revealed an intrusion in Asia involving the BellaCiao .NET malware, as the...

Malicious Apps On Amazon Appstore Records Screen And Interecpt OTP Verifications

A seemingly benign health app, "BMI CalculationVsn," was found on the Amazon App Store,...