Tracking Adversaries: Scattered Spider, the BlackCat affiliate
ID: 21bf6402-0394-5b0c-860a-94b4c8575181
STIX ID: report--21bf6402-0394-5b0c-860a-94b4c8575181
Feed Name: BushidoToken Blog
This analysis describes OSINT and technical overlaps suggesting the English-speaking Scattered Spider group has begun collaborating with or operating as an affiliate of the BlackCat (ALPHV) ransomware ecosystem. It highlights Scattered Spider’s credential-harvesting social-engineering methods (SMS phishing, vishing, MFA fatigue, SIM swap), use of commercial RMM tools and defense-evasion techniques (Microsoft-signed malicious drivers, BYOVD, UEFI BlackLotus), and links these TTPs and IOCs to data theft/ransom incidents such as the Reddit and Riot Games intrusions, concluding the group may have shifted tactics toward ransomware campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
