logo

FBI: Watch out for these signs Scattered Spider is spinning its web around your org

ID: 4d92b520-dace-5d8b-b2a3-ce3fb72b3706

STIX ID: report--4d92b520-dace-5d8b-b2a3-ce3fb72b3706

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2025-07-29

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

A multi‑agency advisory warns that the Scattered Spider extortion group (tracked as UNC3944) has updated tactics to use sophisticated social engineering against helpdesks, harvest Snowflake credentials, deploy remote access tools (Teleport/AnyDesk), and use a Java RAT (RattyRAT) plus DragonForce ransomware to rapidly exfiltrate and/or encrypt data—including targeting ESXi hypervisors and exfiltrating large datasets to MEGA and cloud storage; the bulletin lists sample malicious domains and recommends offline backups, phishing‑resistant MFA, and application control.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.