Parisi, T. (2022, December 2). Not a SIMulation: CrowdStrike Investigations Reveal Intrusion Campaign Targeting Telco and BPO Companies. Retrieved June 30, 2023.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.006 DCSync |
CampaignC0027 | During C0027, Scattered Spider performed domain replication. |
| T1021.007 Cloud Services |
CampaignC0027 | During C0027, Scattered Spider used compromised Azure credentials for credential theft activity and lateral movement to on-premises systems. |
| T1046 Network Service Discovery |
CampaignC0027 | During C0027, used RustScan to scan for open ports on targeted ESXi appliances. |
| T1047 Windows Management Instrumentation |
CampaignC0027 | During C0027, Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket. |
| T1069.003 Cloud Groups |
CampaignC0027 | During C0027, Scattered Spider accessed Azure AD to download bulk lists of group members and their Active Directory attributes. |
| T1078.004 Cloud Accounts |
CampaignC0027 | During C0027, Scattered Spider leveraged compromised credentials from victim users to authenticate to Azure tenants. |
| T1087.003 Email Account |
CampaignC0027 | During C0027, Scattered Spider accessed Azure AD to identify email addresses. |
| T1087.004 Cloud Account |
CampaignC0027 | During C0027, Scattered Spider accessed Azure AD to download bulk lists of group members and to identify privileged users, along with the email addresses and AD attributes. |
| T1090 Proxy |
CampaignC0027 | During C0027, Scattered Spider installed the open-source rsocx reverse proxy tool on a targeted ESXi appliance. |
| T1098.001 Additional Cloud Credentials |
CampaignC0027 | During C0027, Scattered Spider used aws_consoler to create temporary federated credentials for fake users in order to obfuscate which AWS credential is compromised and enable pivoting from the AWS CLI to console sessions without MFA. |
| T1098.003 Additional Cloud Roles |
CampaignC0027 | During C0027, Scattered Spider used IAM manipulation to gain persistence and to assume or elevate privileges. |
| T1098.005 Device Registration |
CampaignC0027 | During C0027, Scattered Spider registered devices for MFA to maintain persistence through victims' VPN. |
| T1102 Web Service |
CampaignC0027 | During C0027, Scattered Spider downloaded tools from sites including file.io, GitHub, and paste.ee. |
| T1105 Ingress Tool Transfer |
CampaignC0027 | During C0027, Scattered Spider downloaded tools using victim organization systems. |
| T1133 External Remote Services |
CampaignC0027 | During C0027, Scattered Spider used Citrix and VPNs to persist in compromised environments. |
| T1190 Exploit Public-Facing Application |
CampaignC0027 | During C0027, Scattered Spider exploited CVE-2021-35464 in the ForgeRock Open Access Management (OpenAM) application server to gain initial access. |
| T1213.002 Sharepoint |
CampaignC0027 | During C0027, Scattered Spider accessed victim SharePoint environments to search for VPN and MFA enrollment information, help desk instructions, and new hire guides. |
| T1219.002 Remote Desktop Software |
CampaignC0027 | During C0027, Scattered Spider directed victims to run remote monitoring and management (RMM) tools. |
| T1530 Data from Cloud Storage |
CampaignC0027 | During C0027, Scattered Spider accessed victim OneDrive environments to search for VPN and MFA enrollment information, help desk instructions, and new hire guides. |
| T1566.004 Spearphishing Voice |
CampaignC0027 | During C0027, Scattered Spider impersonated legitimate IT personnel in phone calls to direct victims to download a remote monitoring and management (RMM) tool that would allow the adversary to remotely control their system. |
| T1572 Protocol Tunneling |
CampaignC0027 | During C0027, Scattered Spider used SSH tunneling in targeted environments. |
| T1578.002 Create Cloud Instance |
CampaignC0027 | During C0027, Scattered Spider used access to the victim's Azure tenant to create Azure VMs. |
| T1588.002 Tool |
CampaignC0027 | During C0027, Scattered Spider obtained and used multiple tools including the LINpeas privilege escalation utility, aws_consoler, rsocx reverse proxy, Level RMM tool, and RustScan port scanner. |
| T1589.001 Credentials |
CampaignC0027 | During C0027, Scattered Spider sent phishing messages via SMS to steal credentials. |
| T1598.001 Spearphishing Service |
CampaignC0027 | During C0027, Scattered Spider sent Telegram messages impersonating IT personnel to harvest credentials. |
| T1598.004 Spearphishing Voice |
CampaignC0027 | During C0027, Scattered Spider used phone calls to instruct victims to navigate to credential-harvesting websites. |
| T1621 Multi-Factor Authentication Request Generation |
CampaignC0027 | During C0027, Scattered Spider attempted to gain access by continuously sending MFA messages to the victim until they accept the MFA push challenge. |
| T1684.001 Impersonation |
CampaignC0027 | During C0027, Scattered Spider impersonated legitimate IT personnel in phone calls and text messages either to direct victims to a credential harvesting site or getting victims to run commercial remote monitoring and management (RMM) tools. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.