Scattered Spider, BlackCat claw their way back from criminal underground
ID: 40f2790f-f424-5343-8fbc-d1c4c0f6288a
STIX ID: report--40f2790f-f424-5343-8fbc-d1c4c0f6288a
Feed Name: The Register (Security)
The article describes the reemergence of organized ransomware groups (Scattered Spider and BlackCat/ALPHV and affiliated crews) conducting high-impact social-engineering-driven intrusions using new tooling (RansomHub/Cicada), defensive-evasion techniques (ESXi VM persistence, credential dumping) and extortion via Microsoft Teams; it highlights large-scale impact (Change Healthcare breach affecting millions), law enforcement actions, and stresses that these decentralized criminal operations remain active and evasive while defenders should harden help-desk controls, MFA bypass protections, endpoint and network monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
