Scattered Spider
Scattered Spider, a highly active hacking group, has made headlines by targeting more than 130 organizations, with the number of victims steadily increasing.
Scattered Spider is an active cybercriminal group targeting large organizations using advanced social engineering and smishing.
Scattered Spider (also tracked as UNC3944, Oktapus, Octo Tempest) is a highly active cybercriminal group that primarily targets large organizations through advanced social engineering and smishing. The group focuses on sectors such as telecommunications, BPO, technology, hospitality, and retail. Their TTPs include spearphishing links for credential harvesting, deployment of WarzoneRAT and Raccoon Stealer, and leveraging BlackCat ransomware, alongside tools like Rclone for exfiltration and Code Signing for defense impairment. Defenders should pay close attention to Identity and Access Management (IAM), monitor for SIM swapping indicators, enforce phishing-resistant MFA, and be vigilant against NTDS extraction activity associated with BlackCat ransomware deployment.
Scattered Spider, a highly active hacking group, has made headlines by targeting more than 130 organizations, with the number of victims steadily increasing.
Monitor email server logs for Spearphishing Link operations and track user reports for suspicious links.
Monitor social media activity for unusual usage of Social Media Accounts and verify user authentication when ambiguity arises.
Monitor process creation and command-line logs on Unix/Linux systems to detect Unix Shell command executions.
Restrict remote access and strengthen authentication procedures to limit External Remote Services usage.
Monitor system logs and privileged operations to detect Exploitation for Privilege Escalation attacks.
Monitor user activity to track Valid Accounts usage and detect unusual login attempts.
Monitor Active Directory changes and unusual authentication attempts to detect NTDS credential access attacks.
Monitor API requests and resource changes in the cloud environment to detect Cloud Infrastructure Discovery activity.
Monitor SSH connection attempts and authentication logs to track SSH usage.
Monitor email server configurations and rules to detect Email Forwarding Rule changes.
Monitor network traffic and file transfers to detect Ingress Tool Transfer activity.
Monitor network traffic and data transfers using C2 channels to detect Exfiltration Over C2 Channel activity.
Monitor certificate usage and security tool configurations to detect Code Signing and Disable or Modify Tools activity.
Monitor data encryption and system behavior to detect Data Encrypted for Impact attacks.
Scattered Spider primarily targets organizations using social engineering, smishing, and spearphishing links designed for credential harvesting.
The group is associated with BlackCat ransomware. Defenders should pay close attention to Identity and Access Management (IAM), monitor for SIM swapping indicators, enforce phishing-resistant MFA, and be vigilant against NTDS extraction activity associated with BlackCat ransomware deployment.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.