Mandiant Incident Response. (2025, May 6). Defending Against UNC3944: Cybercrime Hardening Guidance from the Frontlines. Retrieved October 13, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
GroupScattered Spider | Scattered Spider has used network reconnaissance commands for discovery including `ping` and `nltest`. |
| T1021.001 Remote Desktop Protocol |
GroupScattered Spider | Scattered Spider has used RDP to enable lateral movement. |
| T1021.004 SSH |
GroupScattered Spider | Scattered Spider has used SSH to move laterally in victim environments and to access the vSphere vCenter Server GUI. |
| T1078 Valid Accounts |
GroupScattered Spider | Scattered Spider has used compromised credentials for initial access. |
| T1083 File and Directory Discovery |
GroupScattered Spider | Scattered Spider Spider enumerates a target organization for files and directories of interest, including source code, user provisioning, MFA device registration, network diagrams, and shared credentials in documents or spreadsheets. |
| T1219.002 Remote Desktop Software |
GroupScattered Spider | In addition to directing victims to run remote software, Scattered Spider members themselves also deploy RMM software including TeamViewer, AnyDesk, LogMeIn, ngrok, and ConnectWise to establish persistence on the compromised network. |
| T1490 Inhibit System Recovery |
GroupScattered Spider | Scattered Spider has stopped the Volume Shadow Copy service on compromised hosts. |
| T1552.001 Credentials In Files |
GroupScattered Spider | Scattered Spider Spider searches for credential storage documentation on a compromised host. |
| T1555.005 Password Managers |
GroupScattered Spider | Scattered Spider has searched for credentials in password vaults and Privileged Access Management (PAM) solutions including HashiCorp Vault. |
| T1580 Cloud Infrastructure Discovery |
GroupScattered Spider | Scattered Spider enumerates cloud environments including Amazon Web Services (AWS) S3 buckets to identify server and backup management infrastructure, resource access, databases and storage containers . |
| T1588.001 Malware |
GroupScattered Spider | Scattered Spider has obtained malware to use at multiple stages of operations including information stealers, remote access tools, and ransomware. |
| T1588.002 Tool |
GroupScattered Spider | Scattered Spider has obtained tools for use throughout the attack lifecycle to include remote access software, protocol tunneling and proxy tools, exploitation frameworks, and reconnaissance tools. |
| T1684.001 Impersonation |
GroupScattered Spider | Scattered Spider utilized social engineering to compel IT help desk personnel to reset passwords and MFA tokens. Scattered Spider has also used Microsoft Teams to pose as internal IT support or help desk personnel. |
| T1685 Disable or Modify Tools |
GroupScattered Spider | Scattered Spider has uninstalled and disabled security tools. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.