SCATTERED SPIDER Hackers Target IT Support Teams & Bypass Multi-Factor Authentication
A cybercriminal group named SCATTERED SPIDER has emerged as a significant threat, targeting sectors such as hospitality, telecommunications, finance, and retail using advanced techniques.
A cybercriminal group named SCATTERED SPIDER has emerged as a significant threat, targeting sectors such as hospitality, telecommunications, finance, and retail using advanced techniques.
Active since at least 2022, SCATTERED SPIDER distinguishes itself from traditional ransomware actors by combining advanced social engineering with technical expertise. Their method heavily relies on manipulating IT support teams and bypassing multi-factor authentication (MFA) through techniques such as voice phishing (vishing).
The group often impersonates legitimate employees or IT personnel, leveraging their native English fluency and cultural familiarity, which may suggest ties to Western countries. Notable incidents include the attack on MGM Resorts in 2023, where a phone-based attack caused widespread IT disruption.
SCATTERED SPIDER collaborates with DragonForce, a Ransomware-as-a-Service (RaaS) platform that provides customizable payloads, data exfiltration modules, and dark web leak portals for double extortion schemes. This partnership allows the group to focus on initial access via human-centric attacks, while DragonForce handles encryption and ransom negotiations.
Notable incidents include the attack on MGM Resorts in 2023, where a phone-based attack caused widespread IT disruption.
Their attack strategy begins with reconnaissance using open-source intelligence (OSINT) to profile targets and staff. They exploit help desks by impersonating internal personnel to reset MFA or access accounts. Tools like Mimikatz and Cobalt Strike are used for credential harvesting, privilege escalation, and data exfiltration before deploying ransomware.
Their deep understanding of Western corporate environments allows them to navigate complex IT systems, targeting SSO services and remote access tools like VPNs and RDP gateways. They use legitimate administrative tools, known as "Living off the Land" techniques, disable security controls, and delete logs, complicating forensic analysis and incident response.
For organizations, defending against SCATTERED SPIDER requires a focus on both technology and human factors. Reinforcing help desk protocols with strict identity verification and call-back procedures, along with phishing-resistant MFA like hardware tokens, can thwart initial access attempts. Deploying EDR/XDR solutions for behavioral monitoring and auditing identity systems for suspicious activity are also critical.
Ultimately, fostering a security culture through training and crisis simulations is essential to counter this evolving threat, which exploits the human element at the core of corporate operations.
Based on reporting by GBHackers.
