logo

Emulating and Detecting Scattered Spider-like Attacks

ID: 4cc08c42-9a1c-5138-b1cf-25c5ea5419f8

STIX ID: report--4cc08c42-9a1c-5138-b1cf-25c5ea5419f8

Feed Name: Sekoia.io Blog

Threat Score
70/100

Date Published: 2024-07-24

Date Updated: 2026-04-29

Author: Sekoia TDR, Mitigant, Guillaume C., Erwan Chevalier and Kennedy Torkura

...
...

This blog post demonstrates an emulated Scattered Spider-like campaign against a fictitious FinTech's AWS environment using Mitigant Cloud Attack Emulation and Sekoia's SOC/XDR products. It walks through the attack stages (initial access via phishing, enabling EC2 serial console, IAM backdoors and access key creation, password policy degradation, VPC/subnet deletion, Lambda credential compromise, and malicious S3 replication for exfiltration), maps them to MITRE ATT&CK techniques, describes detections and noisy events, and provides lessons learned for adopting a Threat-Informed Defense strategy in cloud environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.