Scattered Spider x RansomHub: A New Partnership
ID: 3d0827a0-8e4b-556a-a6d5-076639c9faeb
STIX ID: report--3d0827a0-8e4b-556a-a6d5-076639c9faeb
Feed Name: ReliaQuest Blog
ReliaQuest investigated an October 2024 intrusion against a manufacturing customer attributed to the English-speaking Scattered Spider collective working as a RansomHub affiliate; attackers used repeated social-engineering calls to the help desk to reset Okta credentials (including a domain admin), enrolled a VOIP MFA device, accessed Thycotic to retrieve ESXi credentials, created a VM on the victim's ESXi host to evade EDR, copied NTDS.dit, exfiltrated data to cloud storage, sabotaged backups (local VeraCrypt and Cohesity cloud deletes), and deployed a RansomHub encryptor—moving from initial compromise to widespread impact in roughly six hours—while the report details observed IOCs, attacker infrastructure, and remediation/mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
