Understanding threat actor capabilities is only half the battle—the other half is knowing whether your organization is in their crosshairs. See how Bitsight threat intelligence helps you move from observation to action.
Scattered Spider remains a highly active social-engineering-driven cybercriminal threat targeting large enterprises and commercial sectors. CISA and partner agencies have highlighted Scattered Spider activity involving sophisticated helpdesk impersonation, MFA bypass, SIM swapping, data extortion, and ransomware activity. Recent reporting also links Scattered Spider or Scattered Spider-linked clusters to major incidents affecting airlines, retailers, insurers, casino and hospitality organizations, and Jaguar Land Rover.
Helpdesk social engineering
Phishing
Voice phishing
MFA push bombing
SIM swapping
Credential theft
Weak identity verification procedures
Over-permissioned remote access tools
Exposed remote access services
Third-party IT provider access
Insufficient monitoring of legitimate tunneling and remote management tools
Social engineering
Helpdesk impersonation
Phishing
Voice phishing
SMS phishing
MFA bombing
SIM swapping
Credential theft
Account takeover
Data theft
Data extortion
Ransomware deployment
Living-off-the-land
Remote access tool abuse
Tunneling service abuse
Legitimate software abuse
Identity provider abuse
Cloud environment access
Lateral movement
Privilege escalation
Data exfiltration
Cryptocurrency theft
Scattered Spider uses helpdesk impersonation, phishing, vishing, MFA bypass, SIM swapping, remote access tools, data theft, extortion, and ransomware deployment.
Enhance employee awareness of phishing, vishing, MFA bombing, and helpdesk impersonation
Use phishing-resistant multifactor authentication
Enforce strict identity verification procedures for helpdesk password resets and MFA resets
Monitor for SIM swapping indicators and suspicious account recovery activity
Detect and restrict unauthorized use of remote access and tunneling tools
Monitor for unusual activity involving Ngrok, Tailscale, ScreenConnect, AnyDesk, TeamViewer, Splashtop, and similar tools
Harden identity provider policies and monitor for suspicious authentication behavior
Limit access to remote desktop services and administrative tools
Strengthen third-party IT provider access controls
Develop and test incident response plans for data extortion and ransomware scenarios
Understanding threat actor capabilities is only half the battle—the other half is knowing whether your organization is in their crosshairs. See how Bitsight threat intelligence helps you move from observation to action.