Scattered Spider Ramps Up Ransomware In 2025 Cyber Alert
ID: 7d0a2bad-ac82-52a3-820b-356947376130
STIX ID: report--7d0a2bad-ac82-52a3-820b-356947376130
Feed Name: Cyble Blog
Joint advisory (ASD, ACSC, FBI, CISA, NCSC, and others) updated July 2025 warns that Scattered Spider (UNC3944/Oktapus) has escalated from credential and data-theft operations to deploying DragonForce ransomware, combining large-scale exfiltration (Amazon S3, MEGA, cloud services) with ESXi and enterprise system encryption; the group uses sophisticated social engineering (SIM swap, MFA fatigue, vishing), SSO/federated identity abuse, living-off-the-land and legitimate RMM/tunneling tools, and a malware toolkit (AveMaria, Raccoon, VIDAR, RattyRAT) to maintain persistence, move laterally, and monitor internal communications — agencies urge enhanced identity controls, threat hunting, red teaming, and strict remote-access governance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
