Tracking Scattered Spider Through Identity Attacks and Token Theft
ID: d9f64497-04de-5207-9cc2-ecc70f088764
STIX ID: report--d9f64497-04de-5207-9cc2-ecc70f088764
Feed Name: Resources-2
Scattered Spider (UNC3944) is a financially motivated threat actor active since 2022 that uses aggressive social engineering (SIM swapping, helpdesk impersonation, AiTM phishing) and OAuth/session token theft to hijack identities; the group has deployed modular phishing kits and integrated a custom Spectre RAT for stealthy, fileless persistence and reconnaissance, and is linked to ransomware affiliates (e.g., ALPHV/BlackCat). The report maps their TTPs to MITRE ATT&CK, details phishing kit and C2 artifacts, and recommends validation and detection exercises (e.g., Picus simulations) to reduce identity-based exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
