ATT&CKReferencesCrowdStrike Scattered Spider BYOVD January 2023

CrowdStrike Scattered Spider BYOVD January 2023

CrowdStrike. (2023, January 10). SCATTERED SPIDER Exploits Windows Security Deficiencies with Bring-Your-Own-Vulnerable-Driver Tactic in Attempt to Bypass Endpoint Security. Retrieved July 5, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1068
Exploitation for Privilege Escalation
GroupScattered Spider

Scattered Spider has deployed a malicious kernel driver through exploitation of CVE-2015-2291 in the Intel Ethernet diagnostics driver for Windows (iqvw64.sys).

T1133
External Remote Services
GroupScattered Spider

Scattered Spider has leveraged legitimate remote management tools to maintain persistent access.

T1553.002
Code Signing
GroupScattered Spider

Scattered Spider has used self-signed and stolen certificates originally issued to NVIDIA and Global Software LLC.

T1598
Phishing for Information
GroupScattered Spider

Scattered Spider has used a combination of credential phishing and social engineering to capture one-time-password (OTP) codes.

T1621
Multi-Factor Authentication Request Generation
GroupScattered Spider

Scattered Spider has used multifactor authentication (MFA) fatigue by sending repeated MFA authentication requests to targets.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.