logo

CrowdStrike Services Observes SCATTERED SPIDER Escalate Attacks Across Industries

ID: 7f5ebd9d-9d9f-5156-bfb0-a8ad52dacbe5

STIX ID: report--7f5ebd9d-9d9f-5156-bfb0-a8ad52dacbe5

Feed Name: Crowdstrike Blog

Threat Score
80/100

Date Published: 2025-07-02

Date Updated: 2026-04-27

Author: Counter Adversary Operations

...
...

This CrowdStrike report details SCATTERED SPIDER, an eCrime adversary that uses sophisticated phone-based social engineering (help desk voice phishing and SIM swapping) to compromise Entra ID/SSO/VDI accounts, pivot into SaaS and cloud environments, abuse VMware vCenter/ESXi (including creating unmanaged VMs and dumping ntds.dit), exfiltrate data to attacker-controlled S3 buckets, and deploy ransomware or threaten data leaks; the report lists observed TTPs, affected sectors (insurance, retail, and recently aviation), and provides prioritized detection, correlation rules, and hardening recommendations via the CrowdStrike Falcon platform.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.