ATT&CKReferencesMandiant UNC3944 May 2025

Mandiant UNC3944 May 2025

Mandiant Incident Response. (2025, May 6). Defending Against UNC3944: Cybercrime Hardening Guidance from the Frontlines. Retrieved October 13, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
GroupScattered Spider

Scattered Spider has used network reconnaissance commands for discovery including `ping` and `nltest`.

T1021.001
Remote Desktop Protocol
GroupScattered Spider

Scattered Spider has used RDP to enable lateral movement.

T1021.004
SSH
GroupScattered Spider

Scattered Spider has used SSH to move laterally in victim environments and to access the vSphere vCenter Server GUI.

T1078
Valid Accounts
GroupScattered Spider

Scattered Spider has used compromised credentials for initial access.

T1083
File and Directory Discovery
GroupScattered Spider

Scattered Spider Spider enumerates a target organization for files and directories of interest, including source code, user provisioning, MFA device registration, network diagrams, and shared credentials in documents or spreadsheets.

T1219.002
Remote Desktop Software
GroupScattered Spider

In addition to directing victims to run remote software, Scattered Spider members themselves also deploy RMM software including TeamViewer, AnyDesk, LogMeIn, ngrok, and ConnectWise to establish persistence on the compromised network.

T1490
Inhibit System Recovery
GroupScattered Spider

Scattered Spider has stopped the Volume Shadow Copy service on compromised hosts.

T1552.001
Credentials In Files
GroupScattered Spider

Scattered Spider Spider searches for credential storage documentation on a compromised host.

T1555.005
Password Managers
GroupScattered Spider

Scattered Spider has searched for credentials in password vaults and Privileged Access Management (PAM) solutions including HashiCorp Vault.

T1580
Cloud Infrastructure Discovery
GroupScattered Spider

Scattered Spider enumerates cloud environments including Amazon Web Services (AWS) S3 buckets to identify server and backup management infrastructure, resource access, databases and storage containers .

T1588.001
Malware
GroupScattered Spider

Scattered Spider has obtained malware to use at multiple stages of operations including information stealers, remote access tools, and ransomware.

T1588.002
Tool
GroupScattered Spider

Scattered Spider has obtained tools for use throughout the attack lifecycle to include remote access software, protocol tunneling and proxy tools, exploitation frameworks, and reconnaissance tools.

T1684.001
Impersonation
GroupScattered Spider

Scattered Spider utilized social engineering to compel IT help desk personnel to reset passwords and MFA tokens. Scattered Spider has also used Microsoft Teams to pose as internal IT support or help desk personnel.

T1685
Disable or Modify Tools
GroupScattered Spider

Scattered Spider has uninstalled and disabled security tools.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.