ATT&CKReferencesCheck Point Scattered Spider JUL 2025

Check Point Scattered Spider JUL 2025

Check Point Team. (2025, July 7). Exposing Scattered Spider: New Indicators Highlight Growing Threat to Enterprises and Aviation. Retrieved October 13, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1219.002
Remote Desktop Software
GroupScattered Spider

In addition to directing victims to run remote software, Scattered Spider members themselves also deploy RMM software including TeamViewer, AnyDesk, LogMeIn, ngrok, and ConnectWise to establish persistence on the compromised network.

T1486
Data Encrypted for Impact
GroupScattered Spider

Scattered Spider has used BlackCat and DragonForce ransomware to encrypt files including on VMWare ESXi servers.

T1583.001
Domains
GroupScattered Spider

Scattered Spider has registered domains to spoof legitimate corporate login portals.

T1588.001
Malware
GroupScattered Spider

Scattered Spider has obtained malware to use at multiple stages of operations including information stealers, remote access tools, and ransomware.

T1588.002
Tool
GroupScattered Spider

Scattered Spider has obtained tools for use throughout the attack lifecycle to include remote access software, protocol tunneling and proxy tools, exploitation frameworks, and reconnaissance tools.

T1598.003
Spearphishing Link
GroupScattered Spider

Scattered Spider has used domains mirroring corporate login portals to socially engineer victims into providing credentials.

T1621
Multi-Factor Authentication Request Generation
GroupScattered Spider

Scattered Spider has used multifactor authentication (MFA) fatigue by sending repeated MFA authentication requests to targets.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.