Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    ‘Less pitching, more listening’: What Amazon is really doing at CES

    The definitive Digiday guide to what’s in and out for advertising in 2026

    Omnicom Media kicks off CES with a Google search partner that drills deeper into intent

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      A new pope, political shake-ups and celebs in space: The 2025-in-review news quiz

      December 31, 2025

      AI has become the norm for students. Teachers are playing catch-up.

      December 23, 2025

      Trump signs executive order seeking to ban states from regulating AI companies

      December 13, 2025

      Apple’s AI chief abruptly steps down

      December 3, 2025

      The issue that’s scrambling both parties: From the Politics Desk

      December 3, 2025
    • Business

      Top 10 cloud computing stories of 2025

      December 22, 2025

      Saudia Arabia’s STC commits to five-year network upgrade programme with Ericsson

      December 18, 2025

      Zeroday Cloud hacking event awards $320,0000 for 11 zero days

      December 18, 2025

      Amazon: Ongoing cryptomining campaign uses hacked AWS accounts

      December 18, 2025

      Want to back up your iPhone securely without paying the Apple tax? There’s a hack for that, but it isn’t for everyone… yet

      December 16, 2025
    • Crypto

      Aave Price Jumps Amid Revenue Sharing Plans With Token Holders

      January 3, 2026

      Grayscale Predicts Bitcoin Will Reach New All-Time High by March 2026

      January 3, 2026

      Tom Lee Pushes for Big Share Increase as BitMine Closely Tracks Ethereum Price

      January 3, 2026

      Bitfinex Hacker Out of Prison After a Year Due to President Trump’s First Step Act

      January 3, 2026

      Will 2026 Deliver an Extreme Crypto Bear Market? Experts Weigh In

      January 3, 2026
    • Technology

      ‘Less pitching, more listening’: What Amazon is really doing at CES

      January 5, 2026

      The definitive Digiday guide to what’s in and out for advertising in 2026

      January 5, 2026

      Omnicom Media kicks off CES with a Google search partner that drills deeper into intent

      January 5, 2026

      The accidental guardian: How Cloudflare’s Matthew Prince became publishing’s unexpected defender

      January 5, 2026

      The AI hype cycle is rewriting ad tech’s M&A math

      January 5, 2026
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»Scattered Spider tactics continue to evolve, warn cyber cops
    Technology

    Scattered Spider tactics continue to evolve, warn cyber cops

    TechAiVerseBy TechAiVerseJuly 31, 2025No Comments5 Mins Read2 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Scattered Spider tactics continue to evolve, warn cyber cops
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    Scattered Spider tactics continue to evolve, warn cyber cops

    CISA, the FBI, NCSC and others have clubbed together to update previous guidance on Scattered Spider’s playbook, warning of new social engineering tactics and exploitation of legitimate tools, among other things.

    By

    • Alex Scroxton,
      Security Editor

    Published: 30 Jul 2025 17:04

    The Scattered Spider hacking collective is still hard at work refining its tactics and deploying new malware variants in the service of its damaging cyber attacks, according to the cyber security agencies of the US, Australia, Canada and the UK.

    Scattered Spider surged back to prominence earlier in 2025, at first with a round of cyber attacks on UK retailers Marks & Spencer, Co-op Group and Harrods, prior to pivoting to targets in North America, hitting retailer, insurance firms and organisations operating in aviation. Latterly, the gang. Investigations into the gang continue in multiple jurisdictions and the British authorities have arrested a number of individuals who may be linked to the group.

    Now, an updated advisory, issued through through the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), the UK’s National Cyber Security Centre (NCSC) and cyber agencies in Australia and Canada, is warning of updated tactics, techniques and procedures (TTPs) observed through June 2025 by the FBI as it responded to multiple attacks on American targets.

    “Scattered Spider threat actors typically engage in data theft for extortion and also use several ransomware variants, most recently deploying DragonForce ransomware alongside their usual TTPs,” the advisory reads.

    “While some TTPs remain consistent, Scattered Spider threat actors often change TTPs to remain undetected.

    “The authoring organisations encourage critical infrastructure organizations and commercial facilities to implement the recommendations in the Mitigations section of this advisory to reduce the likelihood and impact of Scattered Spider malicious activity.”

    RattyRAT and other surprises

    Historically, Scattered Spider attacks have started with broad phishing and smishing attempts originating from maliciously-crafted, victim-specific domains.

    This continues to be the case, with some minor variants – new domains observed by the FBI of late have included targets name-cms[.]com, targets name-helpdesk[.]com, and oktalogin-targets name[.]com. Scattered Spider has frequently leveraged Okta’s branding in its attacks in the past (one of its other aliases is 0ktapus) and its unrequited love affair with the identity services specialist continues.

    The current wave of attacks is also employing more targeted and multilayered spear phishing and vishing into its playbook, often incorporating legitimate b2b websites to gather information to enrich their attempts and make them seem more convincing.

    Scattered Spider also now appears to be refining its social engineering nous, and has recently been observed posing as victim employees to convince IT or helpdesk staff to provide credential information, run rests, and transfer multifactor authentication (MFA) to devices they control.

    Access established, Scattered Spider has also added a number of new legitimate remote access tunneling tools to its roster of technical expertise. In addition to the likes of Screenconnect and TeamViewer, it is now using AnyDesk to enable remote access to network devices and Teleport.sh and  to enable remote access to local systems.

    The advisory further details a new Java-based remote access trojan dubbed RattyRAT, which Scattered Spider is using to establish persistent and stealthy access and perform internal recon activities within its victims’ infrastructure. The gang is also keeping a close lookout for signs that it has been detected, and besides monitoring internal applications such as Microsoft Teams and Slack, is now making its activity seem more convincing by creating new identities upheld by sock puppet social media profiles.

    The advisory also notes the gang’s by now well-observed affiliation with DragonForce ransomware for data encryption and extortion, and is increasingly targeting VMware ESXi servers in this. When it exfiltrates data in its ransomware attacks – it now also appears to be seeking its victims’ Snowflake access in order to steal more data quicker – it uses multiple sites including MEGA and US-based datacentres including Amazon’s, and uses TOR, Tox, email, and encrypted applications to communicate with its victims.

    The full updated advisory contains a wealth of additional information including MITRE ATT&CK tactics and techniques and mitigation advice.

    It also calls on victims to report incidents to the authorities, subject to local legal requirements, and reiterates guidance not to pay ransoms for encrypted data.

    Takeaways for security leaders

    Nick Tausek, lead security automation architect at Swimlane, an AI security platform provider, said two major points stood out from the updated advisory.

    “First, Scattered Spider’s ability to exfiltrate large amounts of data should raise a lot of red flags. Access to an organisation’s Snowflake allows the group to run thousands of queries immediately and simultaneously, often deploying Dragonforce malware to encrypt target organisations’ servers. The potential for vast amounts of stolen data explains why they’ve been successful across multiple industries, from insurance to transportation to retail,” he said.

    “However, what might be even more disturbing is the diligence exhibited by the group. Entering incident remediation and response calls undetected in order to identify how security teams are adapting to their attacks is a clever strategy to remain ahead. Listening in on these calls gives them access to information like how they’re being hunted, and what adjustments security teams will make to prevent future attacks.

    “Organisations should administer application controls that can prevent remote access authorisation, such as virtual private networks or virtual desktop interfaces. Additionally, organisations should severely limit the use of Remote Desktop Protocol (RDP), and implement recovery plans, such as offline backups of data, in the event that ransomware does breach their security defence,” said Tausek.

    Read more on Hackers and cybercrime prevention


    • Scattered Spider victim Clorox sues helpdesk provider

      By: Alex Scroxton


    • Co-op chief ‘incredibly sorry’ for theft of 6.5m members’ data

      By: Alex Scroxton


    • Scattered Spider playbook evolving fast, says Microsoft

      By: Alex Scroxton


    • Luxury retailer LVMH says UK customer data was stolen in cyber attack

      By: Alex Scroxton

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleApple pushes almost 30 security fixes in mobile update
    Next Article UK flights suspended after air traffic control outage
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    ‘Less pitching, more listening’: What Amazon is really doing at CES

    January 5, 2026

    The definitive Digiday guide to what’s in and out for advertising in 2026

    January 5, 2026

    Omnicom Media kicks off CES with a Google search partner that drills deeper into intent

    January 5, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025581 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025222 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 2025122 Views

    6 Best MagSafe Phone Grips (2025), Tested and Reviewed

    April 6, 2025107 Views
    Don't Miss
    Technology January 5, 2026

    ‘Less pitching, more listening’: What Amazon is really doing at CES

    ‘Less pitching, more listening’: What Amazon is really doing at CES By Seb Joseph  • …

    The definitive Digiday guide to what’s in and out for advertising in 2026

    Omnicom Media kicks off CES with a Google search partner that drills deeper into intent

    The accidental guardian: How Cloudflare’s Matthew Prince became publishing’s unexpected defender

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    ‘Less pitching, more listening’: What Amazon is really doing at CES

    January 5, 20262 Views

    The definitive Digiday guide to what’s in and out for advertising in 2026

    January 5, 20260 Views

    Omnicom Media kicks off CES with a Google search partner that drills deeper into intent

    January 5, 20262 Views
    Most Popular

    What to Know and Where to Find Apple Intelligence Summaries on iPhone

    March 12, 20250 Views

    A Team of Female Founders Is Launching Cloud Security Tech That Could Overhaul AI Protection

    March 12, 20250 Views

    Senua’s Saga: Hellblade 2 leads BAFTA Game Awards 2025 nominations

    March 12, 20250 Views
    © 2026 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.