Threat group.View on attack.mitre.org
Scattered Spider is a native English-speaking cybercriminal group active since at least 2022. The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors.
Scattered Spider relies heavily on social engineering, including impersonating IT and help-desk staff, to gain initial access, bypass multi-factor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain.
Scattered Spider had expanded into hybrid cloud and identity environments, using help-desk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365.
| Technique | Procedure example |
|---|---|
| T1003.003 NTDS |
Scattered Spider has extracted the `NTDS.dit` file by creating volume shadow copies of virtual domain controller disks. |
| T1006 Direct Volume Access |
Scattered Spider has created volume shadow copies of virtual domain controller disks to extract the `NTDS.dit` file. |
| T1016 System Network Configuration Discovery |
Scattered Spider has used network reconnaissance commands for discovery including `ping` and `nltest`. |
| T1018 Remote System Discovery |
Scattered Spider can enumerate remote systems, such as VMware vCenter infrastructure. |
| T1021.001 Remote Desktop Protocol |
Scattered Spider has used RDP to enable lateral movement. |
| T1021.004 SSH |
Scattered Spider has used SSH to move laterally in victim environments and to access the vSphere vCenter Server GUI. |
| T1021.007 Cloud Services |
Scattered Spider has also leveraged pre-existing AWS EC2 instances for lateral movement and data collection purposes. |
| T1041 Exfiltration Over C2 Channel |
Scattered Spider has exfiltrated data from compromised VMware vCenter servers through an established C2 channel using the Teleport remote access tool. |
| T1059.001 PowerShell |
Scattered Spider has used the PowerShell cmdlet Get-ADUser. |
| T1059.004 Unix Shell |
Scattered Spider has used the command shell to upload and install the Teleport remote access tool to a compromised vCenter Server Appliance. |
| T1068 Exploitation for Privilege Escalation |
Scattered Spider has deployed a malicious kernel driver through exploitation of CVE-2015-2291 in the Intel Ethernet diagnostics driver for Windows (iqvw64.sys). |
| T1069 Permission Groups Discovery |
Scattered Spider has enumerated the vSphere Admins and ESX Admins groups in targeted environments. |
| T1069.002 Domain Groups |
Scattered Spider has enumerated Active Directory security groups including through the use of ADExplorer, ADRecon.ps1, and Get-ADUser. |
| T1070.008 Clear Mailbox Data |
Scattered Spider has manually deleted emails notifying users of suspicious account activity. |
| T1074 Data Staged |
Scattered Spider stages data in a centralized database prior to exfiltration. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.