logo

Scattered Spider hackers switch focus to cloud apps for data theft

ID: 334b2f21-60f2-5c70-8df0-e51683766913

STIX ID: report--334b2f21-60f2-5c70-8df0-e51683766913

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-06-14

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

The report describes Scattered Spider (UNC3944/Octo Tempest), a loose criminal collective that has shifted from on-premises account hijacking to targeting cloud infrastructure and SaaS applications for data-theft extortion. Using social engineering against help-desk agents and Okta account abuse, the actor escalates privileges, creates persistent VMs, disables security telemetry, deploys credential-theft and lateral-movement tools, and exfiltrates data via legitimate cloud-sync services to GCP/AWS; the report includes defensive recommendations such as centralized SaaS logging, monitoring MFA re-registrations, and tighter access policies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.