logo

Notorious cyber gang UNC3944 attacks vSphere and Azure to run VMs inside victims' infrastructure

ID: 15768082-bf50-5bc5-bf1c-77d3e9361b28

STIX ID: report--15768082-bf50-5bc5-bf1c-77d3e9361b28

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2024-06-17

Date Updated: 2026-04-26

Author: Simon Sharwood

...
...

UNC3944 (aka 0ktapus/Scattered Spider) has shifted tactics from ransomware to data-theft extortion and is actively targeting SaaS and cloud environments. Mandiant observed the group using social-engineering phone calls to bypass help-desk identity checks and force MFA resets, compromising SSO providers (e.g., Okta) and cloud management tools to create persistent access and exfiltrate data using synchronization utilities like Airbyte and Fivetran. Organizations are advised to centralize SaaS logging, monitor MFA re-registrations and VM creation, and increase detection around SSO and cloud infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.