Notorious cyber gang UNC3944 attacks vSphere and Azure to run VMs inside victims' infrastructure
ID: 15768082-bf50-5bc5-bf1c-77d3e9361b28
STIX ID: report--15768082-bf50-5bc5-bf1c-77d3e9361b28
Feed Name: The Register (Security)
UNC3944 (aka 0ktapus/Scattered Spider) has shifted tactics from ransomware to data-theft extortion and is actively targeting SaaS and cloud environments. Mandiant observed the group using social-engineering phone calls to bypass help-desk identity checks and force MFA resets, compromising SSO providers (e.g., Okta) and cloud management tools to create persistent access and exfiltrate data using synchronization utilities like Airbyte and Fivetran. Organizations are advised to centralize SaaS logging, monitor MFA re-registrations and VM creation, and increase detection around SSO and cloud infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
