logo

Scattered Spider Ramps Up Ransomware In 2025 Cyber Alert

ID: 7d0a2bad-ac82-52a3-820b-356947376130

STIX ID: report--7d0a2bad-ac82-52a3-820b-356947376130

Feed Name: Cyble Blog

Threat Score
85/100

Date Published: 2025-08-04

Date Updated: 2026-07-20

...
...

Joint advisory (ASD, ACSC, FBI, CISA, NCSC, and others) updated July 2025 warns that Scattered Spider (UNC3944/Oktapus) has escalated from credential and data-theft operations to deploying DragonForce ransomware, combining large-scale exfiltration (Amazon S3, MEGA, cloud services) with ESXi and enterprise system encryption; the group uses sophisticated social engineering (SIM swap, MFA fatigue, vishing), SSO/federated identity abuse, living-off-the-land and legitimate RMM/tunneling tools, and a malware toolkit (AveMaria, Raccoon, VIDAR, RattyRAT) to maintain persistence, move laterally, and monitor internal communications — agencies urge enhanced identity controls, threat hunting, red teaming, and strict remote-access governance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.