Spidering Through Identity for Profit and Disruption
ID: 274c5e0a-e0c0-574f-9167-6d4e4e857536
STIX ID: report--274c5e0a-e0c0-574f-9167-6d4e4e857536
Feed Name: Huntress Blog
**Executive summary:** In September 2023, widespread disruptions at MGM Resorts and a prior intrusion at Caesars Entertainment were linked to identity-focused intrusions attributed to the criminal group known as Scattered Spider, with potential follow-on ransomware activity (ALPHV/BlackCat). The report highlights attacker tactics—social engineering of IT personnel, credential capture, SIM swapping, MFA fatigue, and abuse of legitimate RMM/LOLBIN tools—argues defenders must extend monitoring to cloud and third‑party identity services, and recommends identity‑centric detections and controls (logon profiling, correlation of MFA abuse, isolation of compromised identities) alongside broader zero‑trust approaches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
