logo

Scattered Spider x RansomHub: A New Partnership

ID: 3d0827a0-8e4b-556a-a6d5-076639c9faeb

STIX ID: report--3d0827a0-8e4b-556a-a6d5-076639c9faeb

Feed Name: ReliaQuest Blog

Threat Score
85/100

Date Published: 2024-10-24

Date Updated: 2026-04-29

...
...

ReliaQuest investigated an October 2024 intrusion against a manufacturing customer attributed to the English-speaking Scattered Spider collective working as a RansomHub affiliate; attackers used repeated social-engineering calls to the help desk to reset Okta credentials (including a domain admin), enrolled a VOIP MFA device, accessed Thycotic to retrieve ESXi credentials, created a VM on the victim's ESXi host to evade EDR, copied NTDS.dit, exfiltrated data to cloud storage, sabotaged backups (local VeraCrypt and Cohesity cloud deletes), and deployed a RansomHub encryptor—moving from initial compromise to widespread impact in roughly six hours—while the report details observed IOCs, attacker infrastructure, and remediation/mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.