ATT&CKReferencesCISA Scattered Spider Advisory November 2023

CISA Scattered Spider Advisory November 2023

CISA. (2023, November 16). Cybersecurity Advisory: Scattered Spider (AA23-320A). Retrieved March 18, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples28

TechniqueUsed byProcedure example
T1018
Remote System Discovery
GroupScattered Spider

Scattered Spider can enumerate remote systems, such as VMware vCenter infrastructure.

T1021.007
Cloud Services
GroupScattered Spider

Scattered Spider has also leveraged pre-existing AWS EC2 instances for lateral movement and data collection purposes.

T1074
Data Staged
GroupScattered Spider

Scattered Spider stages data in a centralized database prior to exfiltration.

T1083
File and Directory Discovery
GroupScattered Spider

Scattered Spider Spider enumerates a target organization for files and directories of interest, including source code, user provisioning, MFA device registration, network diagrams, and shared credentials in documents or spreadsheets.

T1087.002
Domain Account
GroupScattered Spider

Scattered Spider has enumerated legitimate domain accounts which are used in the targeted environment.

T1090
Proxy
GroupScattered Spider

Scattered Spider has used proxy networks to hamper detection and has installed legitimate proxy tools on VMware vCenter and adversary-controlled VMs.

T1114
Email Collection
GroupScattered Spider

Scattered Spider searched the victim’s Microsoft Exchange for emails about the intrusion and incident response.

T1136
Create Account
GroupScattered Spider

Scattered Spider creates new user identities within the compromised organization.

T1204
User Execution
GroupScattered Spider

Scattered Spider has impersonated organization IT and helpdesk staff to instruct victims to execute commercial remote access tools to gain initial access.

T1213.003
Code Repositories
GroupScattered Spider

Scattered Spider enumerates data stored within victim code repositories, such as internal GitHub repositories.

T1213.005
Messaging Applications
GroupScattered Spider

Scattered Spider threat actors search the victim’s Slack and Microsoft Teams for conversations about the intrusion and incident response.

T1217
Browser Information Discovery
GroupScattered Spider

Scattered Spider retrieves browser histories via infostealer malware such as Raccoon Stealer.

T1219.002
Remote Desktop Software
GroupScattered Spider

In addition to directing victims to run remote software, Scattered Spider members themselves also deploy RMM software including TeamViewer, AnyDesk, LogMeIn, ngrok, and ConnectWise to establish persistence on the compromised network.

T1484.002
Trust Modification
GroupScattered Spider

Scattered Spider adds a federated identity provider to the victim’s SSO tenant and activates automatic account linking.

T1486
Data Encrypted for Impact
GroupScattered Spider

Scattered Spider has used BlackCat and DragonForce ransomware to encrypt files including on VMWare ESXi servers.

T1530
Data from Cloud Storage
GroupScattered Spider

Scattered Spider enumerates data stored in cloud resources for collection and exfiltration purposes.

T1538
Cloud Service Dashboard
GroupScattered Spider

Scattered Spider abused AWS Systems Manager Inventory to identify targets on the compromised network prior to lateral movement.

T1539
Steal Web Session Cookie
GroupScattered Spider

Scattered Spider retrieves browser cookies via Raccoon Stealer.

T1552.001
Credentials In Files
GroupScattered Spider

Scattered Spider Spider searches for credential storage documentation on a compromised host.

T1552.004
Private Keys
GroupScattered Spider

Scattered Spider enumerate and exfiltrate code-signing certificates from a compromised host.

T1556.006
Multi-Factor Authentication
GroupScattered Spider

After compromising user accounts, Scattered Spider registers their own MFA tokens.

T1567.002
Exfiltration to Cloud Storage
GroupScattered Spider

Scattered Spider has exfiltrated victim data to the MEGA file sharing site, SnowFlake, and AWS S3 buckets.

T1572
Protocol Tunneling
GroupScattered Spider

Scattered Spider has installed protocol-tunneling tools on VMware vCenter and adversary-controlled VMs, including Teleport.sh, Chisel (configured to communicate with trycloudflare[.]com subdomains), MobaXterm, ngrok, Pinggy, and Teleport.

T1578.002
Create Cloud Instance
GroupScattered Spider

Scattered Spider has created Amazon EC2 instances within the victim's environment.

T1585.001
Social Media Accounts
GroupScattered Spider

Scattered Spider has created matching fake social media profiles to support new accounts created in victim environments.

T1588.002
Tool
GroupScattered Spider

Scattered Spider has obtained tools for use throughout the attack lifecycle to include remote access software, protocol tunneling and proxy tools, exploitation frameworks, and reconnaissance tools.

T1657
Financial Theft
GroupScattered Spider

Scattered Spider has deployed ransomware on compromised hosts and threatened to leak stolen data for financial gain.

T1684.001
Impersonation
GroupScattered Spider

Scattered Spider utilized social engineering to compel IT help desk personnel to reset passwords and MFA tokens. Scattered Spider has also used Microsoft Teams to pose as internal IT support or help desk personnel.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.