ATT&CKReferencesCrowdStrike Scattered Spider JUL 2025

CrowdStrike Scattered Spider JUL 2025

Counter Adversary Operations. (2025, July 2). CrowdStrike Services Observes SCATTERED SPIDER Escalate Attacks Across Industries. Retrieved October 13, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1003.003
NTDS
GroupScattered Spider

Scattered Spider has extracted the `NTDS.dit` file by creating volume shadow copies of virtual domain controller disks.

T1059.001
PowerShell
GroupScattered Spider

Scattered Spider has used the PowerShell cmdlet Get-ADUser.

T1069.002
Domain Groups
GroupScattered Spider

Scattered Spider has enumerated Active Directory security groups including through the use of ADExplorer, ADRecon.ps1, and Get-ADUser.

T1070.008
Clear Mailbox Data
GroupScattered Spider

Scattered Spider has manually deleted emails notifying users of suspicious account activity.

T1078.004
Cloud Accounts
GroupScattered Spider

Scattered Spider has used compromised Microsoft Entra ID accounts to pivot in victim environments.

T1083
File and Directory Discovery
GroupScattered Spider

Scattered Spider Spider enumerates a target organization for files and directories of interest, including source code, user provisioning, MFA device registration, network diagrams, and shared credentials in documents or spreadsheets.

T1087.002
Domain Account
GroupScattered Spider

Scattered Spider has enumerated legitimate domain accounts which are used in the targeted environment.

T1090
Proxy
GroupScattered Spider

Scattered Spider has used proxy networks to hamper detection and has installed legitimate proxy tools on VMware vCenter and adversary-controlled VMs.

T1114.003
Email Forwarding Rule
GroupScattered Spider

Scattered Spider has redirected emails notifying users of suspicious account activity.

T1219.002
Remote Desktop Software
GroupScattered Spider

In addition to directing victims to run remote software, Scattered Spider members themselves also deploy RMM software including TeamViewer, AnyDesk, LogMeIn, ngrok, and ConnectWise to establish persistence on the compromised network.

T1486
Data Encrypted for Impact
GroupScattered Spider

Scattered Spider has used BlackCat and DragonForce ransomware to encrypt files including on VMWare ESXi servers.

T1552.001
Credentials In Files
GroupScattered Spider

Scattered Spider Spider searches for credential storage documentation on a compromised host.

T1567.002
Exfiltration to Cloud Storage
GroupScattered Spider

Scattered Spider has exfiltrated victim data to the MEGA file sharing site, SnowFlake, and AWS S3 buckets.

T1572
Protocol Tunneling
GroupScattered Spider

Scattered Spider has installed protocol-tunneling tools on VMware vCenter and adversary-controlled VMs, including Teleport.sh, Chisel (configured to communicate with trycloudflare[.]com subdomains), MobaXterm, ngrok, Pinggy, and Teleport.

T1580
Cloud Infrastructure Discovery
GroupScattered Spider

Scattered Spider enumerates cloud environments including Amazon Web Services (AWS) S3 buckets to identify server and backup management infrastructure, resource access, databases and storage containers .

T1588.002
Tool
GroupScattered Spider

Scattered Spider has obtained tools for use throughout the attack lifecycle to include remote access software, protocol tunneling and proxy tools, exploitation frameworks, and reconnaissance tools.

T1598.004
Spearphishing Voice
GroupScattered Spider

Scattered Spider has used help desk voice-based phishing and also called employees at target organizations and compelled them to navigate to fake login portals using adversary-in-the-middle toolkits.

T1657
Financial Theft
GroupScattered Spider

Scattered Spider has deployed ransomware on compromised hosts and threatened to leak stolen data for financial gain.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.