Scattered Spider Tactics Observed Amid Shift to US Targets
ID: 3b1907b6-4e17-5a15-9e48-029c34b56d03
STIX ID: report--3b1907b6-4e17-5a15-9e48-029c34b56d03
Feed Name: Halcyon Blog
Halcyon’s report profiles Scattered Spider, a highly capable cybercriminal group that uses sophisticated social engineering and technical methods (credential theft, ADCS abuse, signed vulnerable drivers, and legitimate remote-access tools) to rapidly exfiltrate data and deploy ransomware (DragonForce, Qilin, Akira, Play) across hybrid on-prem/cloud environments; the document maps the group’s lifecycle to MITRE ATT&CK, cites high-impact incidents, and provides detection, mitigation, and incident response recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
