logo

Scattered Spider Taps CFO Credentials in 'Scorched Earth' Attack

ID: fa9272c7-1a23-5cd0-938e-c7ee86653c2b

STIX ID: report--fa9272c7-1a23-5cd0-938e-c7ee86653c2b

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2025-06-27

Date Updated: 2026-04-21

Author: Rob Wright

...
...

ReliaQuest observed a four-day Scattered Spider intrusion that began by harvesting a CFO's Oracle Cloud SSO credentials and using help-desk social engineering to reset MFA. Attackers performed Entra ID and SharePoint discovery, gained VDI and VPN access, compromised VMware vCenter to reinstate VMs and extract NTDS.dit, and accessed a CyberArk vault to dump ~1,400 secrets. They escalated to Global Administrator and Exchange Administrator roles, interfered with IR by tampering with mailboxes, executed AzureRunCommands and deleted Azure Firewall policies, and were ultimately evicted with Microsoft assistance before ransomware deployment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.