LUCR-3: Scattered Spider Getting SaaS-y in the Cloud
ID: 347932ae-4290-5a72-8023-0a44771cbc7b
STIX ID: report--347932ae-4290-5a72-8023-0a44771cbc7b
Feed Name: Cloud Chronicles
### Executive Summary LUCR-3 is a financially motivated attacker group targeting Fortune 2000 organizations by compromising Identity Provider accounts (Okta, Azure AD/Entra, PingOne) to access SaaS, CI/CD, and cloud resources for theft of IP, code-signing certificates, and customer data used in extortion; they favor living-off-the-land techniques (web consoles, S3 Browser, CloudShell), MFA bypass and credential acquisition, and employ AWS and IDP-specific persistence and defense-evasion measures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
