CrowdStrike Services Observes SCATTERED SPIDER Escalate Attacks Across Industries
ID: 7f5ebd9d-9d9f-5156-bfb0-a8ad52dacbe5
STIX ID: report--7f5ebd9d-9d9f-5156-bfb0-a8ad52dacbe5
Feed Name: Crowdstrike Blog
This CrowdStrike report details SCATTERED SPIDER, an eCrime adversary that uses sophisticated phone-based social engineering (help desk voice phishing and SIM swapping) to compromise Entra ID/SSO/VDI accounts, pivot into SaaS and cloud environments, abuse VMware vCenter/ESXi (including creating unmanaged VMs and dumping ntds.dit), exfiltrate data to attacker-controlled S3 buckets, and deploy ransomware or threaten data leaks; the report lists observed TTPs, affected sectors (insurance, retail, and recently aviation), and provides prioritized detection, correlation rules, and hardening recommendations via the CrowdStrike Falcon platform.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
