Microsoft: Scattered Spider Widens Web With RansomHub & Qilin
ID: fdd449e9-20fd-508a-a6c1-1a8b12da8c85
STIX ID: report--fdd449e9-20fd-508a-a6c1-1a8b12da8c85
Feed Name: Dark Reading
Date Published: 2024-07-16
Date Updated: 2026-04-21
Author: Kristina Beek, Associate Editor, Dark Reading
Microsoft warns that the threat actor Octo Tempest (Scattered Spider) is using RansomHub and Qilin ransomware in ongoing campaigns, combining sophisticated social engineering (phishing, MFA bombing, SIM swapping, IT impersonation) and identity compromise to target organizations — including developing a Linux encryptor for VMware ESXi and being linked to large incidents such as Caesars and MGM.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
