logo

Socially Savvy Scattered Spider Traps Cloud Admins in Web

ID: f3ae3ca7-5069-588e-b7ac-0ff9c9002ea2

STIX ID: report--f3ae3ca7-5069-588e-b7ac-0ff9c9002ea2

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-09-12

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Scattered Spider (Octo Tempest) has executed targeted, highly convincing phone‑based social‑engineering attacks (smishing/vishing) and phishing that impersonate employees and SSO portals to steal high‑privileged cloud credentials, manipulate MFA, and gain persistent access — leveraging techniques such as SIM swaps, purchased credentials, and abuse of cloud‑native tools (e.g., Azure Special Administration Console, Data Factory) to move into cloud environments and deploy ransomware; EclecticIQ’s analysis (2023–Q2 2024) details these TTPs, impacted SaaS and cloud services, and recommends defensive measures including secure authentication, monitoring, hypervisor/cloud resource security, and domain/typosquatting protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.