Scattered Spider Taps CFO Credentials in 'Scorched Earth' Attack
ID: fa9272c7-1a23-5cd0-938e-c7ee86653c2b
STIX ID: report--fa9272c7-1a23-5cd0-938e-c7ee86653c2b
Feed Name: Dark Reading
ReliaQuest observed a four-day Scattered Spider intrusion that began by harvesting a CFO's Oracle Cloud SSO credentials and using help-desk social engineering to reset MFA. Attackers performed Entra ID and SharePoint discovery, gained VDI and VPN access, compromised VMware vCenter to reinstate VMs and extract NTDS.dit, and accessed a CyberArk vault to dump ~1,400 secrets. They escalated to Global Administrator and Exchange Administrator roles, interfered with IR by tampering with mailboxes, executed AzureRunCommands and deleted Azure Firewall policies, and were ultimately evicted with Microsoft assistance before ransomware deployment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
