logo

Scattered Spider Targets Tech Companies for Help-Desk Exploitation

ID: 2ea67992-c94c-5f8e-aef1-a2498cfc2035

STIX ID: report--2ea67992-c94c-5f8e-aef1-a2498cfc2035

Feed Name: ReliaQuest Blog

Threat Score
80/100

Date Published: 2025-06-05

Date Updated: 2026-04-29

...
...

**Executive summary:** ReliaQuest's analysis outlines Scattered Spider's transition from SIM‑swapping to highly targeted social‑engineering and phishing operations (including Evilginx) that impersonate technology vendors and MSPs to steal high‑value credentials, bypass MFA, and enable ransomware deployments via partnerships with operators like ALPHV and DragonForce; the report provides domain/ASN/registrar IOCs, observed keyword and hosting patterns, examples of tactics (vishing, help‑desk impersonation), and prioritized defensive actions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.