CISA. (2023, November 16). Cybersecurity Advisory: Scattered Spider (AA23-320A). Retrieved March 18, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1018 Remote System Discovery |
GroupScattered Spider | Scattered Spider can enumerate remote systems, such as VMware vCenter infrastructure. |
| T1021.007 Cloud Services |
GroupScattered Spider | Scattered Spider has also leveraged pre-existing AWS EC2 instances for lateral movement and data collection purposes. |
| T1074 Data Staged |
GroupScattered Spider | Scattered Spider stages data in a centralized database prior to exfiltration. |
| T1083 File and Directory Discovery |
GroupScattered Spider | Scattered Spider Spider enumerates a target organization for files and directories of interest, including source code, user provisioning, MFA device registration, network diagrams, and shared credentials in documents or spreadsheets. |
| T1087.002 Domain Account |
GroupScattered Spider | Scattered Spider has enumerated legitimate domain accounts which are used in the targeted environment. |
| T1090 Proxy |
GroupScattered Spider | Scattered Spider has used proxy networks to hamper detection and has installed legitimate proxy tools on VMware vCenter and adversary-controlled VMs. |
| T1114 Email Collection |
GroupScattered Spider | Scattered Spider searched the victim’s Microsoft Exchange for emails about the intrusion and incident response. |
| T1136 Create Account |
GroupScattered Spider | Scattered Spider creates new user identities within the compromised organization. |
| T1204 User Execution |
GroupScattered Spider | Scattered Spider has impersonated organization IT and helpdesk staff to instruct victims to execute commercial remote access tools to gain initial access. |
| T1213.003 Code Repositories |
GroupScattered Spider | Scattered Spider enumerates data stored within victim code repositories, such as internal GitHub repositories. |
| T1213.005 Messaging Applications |
GroupScattered Spider | Scattered Spider threat actors search the victim’s Slack and Microsoft Teams for conversations about the intrusion and incident response. |
| T1217 Browser Information Discovery |
GroupScattered Spider | Scattered Spider retrieves browser histories via infostealer malware such as Raccoon Stealer. |
| T1219.002 Remote Desktop Software |
GroupScattered Spider | In addition to directing victims to run remote software, Scattered Spider members themselves also deploy RMM software including TeamViewer, AnyDesk, LogMeIn, ngrok, and ConnectWise to establish persistence on the compromised network. |
| T1484.002 Trust Modification |
GroupScattered Spider | Scattered Spider adds a federated identity provider to the victim’s SSO tenant and activates automatic account linking. |
| T1486 Data Encrypted for Impact |
GroupScattered Spider | Scattered Spider has used BlackCat and DragonForce ransomware to encrypt files including on VMWare ESXi servers. |
| T1530 Data from Cloud Storage |
GroupScattered Spider | Scattered Spider enumerates data stored in cloud resources for collection and exfiltration purposes. |
| T1538 Cloud Service Dashboard |
GroupScattered Spider | Scattered Spider abused AWS Systems Manager Inventory to identify targets on the compromised network prior to lateral movement. |
| T1539 Steal Web Session Cookie |
GroupScattered Spider | Scattered Spider retrieves browser cookies via Raccoon Stealer. |
| T1552.001 Credentials In Files |
GroupScattered Spider | Scattered Spider Spider searches for credential storage documentation on a compromised host. |
| T1552.004 Private Keys |
GroupScattered Spider | Scattered Spider enumerate and exfiltrate code-signing certificates from a compromised host. |
| T1556.006 Multi-Factor Authentication |
GroupScattered Spider | After compromising user accounts, Scattered Spider registers their own MFA tokens. |
| T1567.002 Exfiltration to Cloud Storage |
GroupScattered Spider | Scattered Spider has exfiltrated victim data to the MEGA file sharing site, SnowFlake, and AWS S3 buckets. |
| T1572 Protocol Tunneling |
GroupScattered Spider | Scattered Spider has installed protocol-tunneling tools on VMware vCenter and adversary-controlled VMs, including Teleport.sh, Chisel (configured to communicate with trycloudflare[.]com subdomains), MobaXterm, ngrok, Pinggy, and Teleport. |
| T1578.002 Create Cloud Instance |
GroupScattered Spider | Scattered Spider has created Amazon EC2 instances within the victim's environment. |
| T1585.001 Social Media Accounts |
GroupScattered Spider | Scattered Spider has created matching fake social media profiles to support new accounts created in victim environments. |
| T1588.002 Tool |
GroupScattered Spider | Scattered Spider has obtained tools for use throughout the attack lifecycle to include remote access software, protocol tunneling and proxy tools, exploitation frameworks, and reconnaissance tools. |
| T1657 Financial Theft |
GroupScattered Spider | Scattered Spider has deployed ransomware on compromised hosts and threatened to leak stolen data for financial gain. |
| T1684.001 Impersonation |
GroupScattered Spider | Scattered Spider utilized social engineering to compel IT help desk personnel to reset passwords and MFA tokens. Scattered Spider has also used Microsoft Teams to pose as internal IT support or help desk personnel. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.