Campaign, Jun 2022 to Dec 2022.View on attack.mitre.org
C0027 was a financially-motivated campaign linked to Scattered Spider that targeted telecommunications and business process outsourcing (BPO) companies from at least June through December of 2022. During C0027 Scattered Spider used various forms of social engineering, performed SIM swapping, and attempted to leverage access from victim environments to mobile carrier networks.
| Technique | Procedure example |
|---|---|
| T1003.006 DCSync |
During C0027, Scattered Spider performed domain replication. |
| T1021.007 Cloud Services |
During C0027, Scattered Spider used compromised Azure credentials for credential theft activity and lateral movement to on-premises systems. |
| T1046 Network Service Discovery |
During C0027, used RustScan to scan for open ports on targeted ESXi appliances. |
| T1047 Windows Management Instrumentation |
During C0027, Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket. |
| T1069.003 Cloud Groups |
During C0027, Scattered Spider accessed Azure AD to download bulk lists of group members and their Active Directory attributes. |
| T1078.004 Cloud Accounts |
During C0027, Scattered Spider leveraged compromised credentials from victim users to authenticate to Azure tenants. |
| T1087.003 Email Account |
During C0027, Scattered Spider accessed Azure AD to identify email addresses. |
| T1087.004 Cloud Account |
During C0027, Scattered Spider accessed Azure AD to download bulk lists of group members and to identify privileged users, along with the email addresses and AD attributes. |
| T1090 Proxy |
During C0027, Scattered Spider installed the open-source rsocx reverse proxy tool on a targeted ESXi appliance. |
| T1098.001 Additional Cloud Credentials |
During C0027, Scattered Spider used aws_consoler to create temporary federated credentials for fake users in order to obfuscate which AWS credential is compromised and enable pivoting from the AWS CLI to console sessions without MFA. |
| T1098.003 Additional Cloud Roles |
During C0027, Scattered Spider used IAM manipulation to gain persistence and to assume or elevate privileges. |
| T1098.005 Device Registration |
During C0027, Scattered Spider registered devices for MFA to maintain persistence through victims' VPN. |
| T1102 Web Service |
During C0027, Scattered Spider downloaded tools from sites including file.io, GitHub, and paste.ee. |
| T1105 Ingress Tool Transfer |
During C0027, Scattered Spider downloaded tools using victim organization systems. |
| T1133 External Remote Services |
During C0027, Scattered Spider used Citrix and VPNs to persist in compromised environments. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.