C0027

C0027

Campaign, Jun 2022 to Dec 2022.View on attack.mitre.org

About this campaign

C0027 was a financially-motivated campaign linked to Scattered Spider that targeted telecommunications and business process outsourcing (BPO) companies from at least June through December of 2022. During C0027 Scattered Spider used various forms of social engineering, performed SIM swapping, and attempted to leverage access from victim environments to mobile carrier networks.

Techniques used28

Procedure examples28

TechniqueProcedure example
T1003.006
DCSync

During C0027, Scattered Spider performed domain replication.

T1021.007
Cloud Services

During C0027, Scattered Spider used compromised Azure credentials for credential theft activity and lateral movement to on-premises systems.

T1046
Network Service Discovery

During C0027, used RustScan to scan for open ports on targeted ESXi appliances.

T1047
Windows Management Instrumentation

During C0027, Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket.

T1069.003
Cloud Groups

During C0027, Scattered Spider accessed Azure AD to download bulk lists of group members and their Active Directory attributes.

T1078.004
Cloud Accounts

During C0027, Scattered Spider leveraged compromised credentials from victim users to authenticate to Azure tenants.

T1087.003
Email Account

During C0027, Scattered Spider accessed Azure AD to identify email addresses.

T1087.004
Cloud Account

During C0027, Scattered Spider accessed Azure AD to download bulk lists of group members and to identify privileged users, along with the email addresses and AD attributes.

T1090
Proxy

During C0027, Scattered Spider installed the open-source rsocx reverse proxy tool on a targeted ESXi appliance.

T1098.001
Additional Cloud Credentials

During C0027, Scattered Spider used aws_consoler to create temporary federated credentials for fake users in order to obfuscate which AWS credential is compromised and enable pivoting from the AWS CLI to console sessions without MFA.

T1098.003
Additional Cloud Roles

During C0027, Scattered Spider used IAM manipulation to gain persistence and to assume or elevate privileges.

T1098.005
Device Registration

During C0027, Scattered Spider registered devices for MFA to maintain persistence through victims' VPN.

T1102
Web Service

During C0027, Scattered Spider downloaded tools from sites including file.io, GitHub, and paste.ee.

T1105
Ingress Tool Transfer

During C0027, Scattered Spider downloaded tools using victim organization systems.

T1133
External Remote Services

During C0027, Scattered Spider used Citrix and VPNs to persist in compromised environments.

View all 28 procedure examples

Attributed groups1

Software1

References1

  1. Crowdstrike TELCO BPO Campaign December 2022 Open source
    Parisi, T. (2022, December 2). Not a SIMulation: CrowdStrike Investigations Reveal Intrusion Campaign Targeting Telco and BPO Companies. Retrieved June 30, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.