logo

Scattered Spider Tactics Observed Amid Shift to US Targets

ID: 3b1907b6-4e17-5a15-9e48-029c34b56d03

STIX ID: report--3b1907b6-4e17-5a15-9e48-029c34b56d03

Feed Name: Halcyon Blog

Threat Score
88/100

Date Published: 2026-03-02

Date Updated: 2026-04-28

...
...

Halcyon’s report profiles Scattered Spider, a highly capable cybercriminal group that uses sophisticated social engineering and technical methods (credential theft, ADCS abuse, signed vulnerable drivers, and legitimate remote-access tools) to rapidly exfiltrate data and deploy ransomware (DragonForce, Qilin, Akira, Play) across hybrid on-prem/cloud environments; the document maps the group’s lifecycle to MITRE ATT&CK, cites high-impact incidents, and provides detection, mitigation, and incident response recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.