Emulating and Detecting Scattered Spider-like Attacks
ID: 4cc08c42-9a1c-5138-b1cf-25c5ea5419f8
STIX ID: report--4cc08c42-9a1c-5138-b1cf-25c5ea5419f8
Feed Name: Sekoia.io Blog
Date Published: 2024-07-24
Date Updated: 2026-04-29
Author: Sekoia TDR, Mitigant, Guillaume C., Erwan Chevalier and Kennedy Torkura
This blog post demonstrates an emulated Scattered Spider-like campaign against a fictitious FinTech's AWS environment using Mitigant Cloud Attack Emulation and Sekoia's SOC/XDR products. It walks through the attack stages (initial access via phishing, enabling EC2 serial console, IAM backdoors and access key creation, password policy degradation, VPC/subnet deletion, Lambda credential compromise, and malicious S3 replication for exfiltration), maps them to MITRE ATT&CK techniques, describes detections and noisy events, and provides lessons learned for adopting a Threat-Informed Defense strategy in cloud environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
