Check Point Team. (2025, July 7). Exposing Scattered Spider: New Indicators Highlight Growing Threat to Enterprises and Aviation. Retrieved October 13, 2025.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1219.002 Remote Desktop Software |
GroupScattered Spider | In addition to directing victims to run remote software, Scattered Spider members themselves also deploy RMM software including TeamViewer, AnyDesk, LogMeIn, ngrok, and ConnectWise to establish persistence on the compromised network. |
| T1486 Data Encrypted for Impact |
GroupScattered Spider | Scattered Spider has used BlackCat and DragonForce ransomware to encrypt files including on VMWare ESXi servers. |
| T1583.001 Domains |
GroupScattered Spider | Scattered Spider has registered domains to spoof legitimate corporate login portals. |
| T1588.001 Malware |
GroupScattered Spider | Scattered Spider has obtained malware to use at multiple stages of operations including information stealers, remote access tools, and ransomware. |
| T1588.002 Tool |
GroupScattered Spider | Scattered Spider has obtained tools for use throughout the attack lifecycle to include remote access software, protocol tunneling and proxy tools, exploitation frameworks, and reconnaissance tools. |
| T1598.003 Spearphishing Link |
GroupScattered Spider | Scattered Spider has used domains mirroring corporate login portals to socially engineer victims into providing credentials. |
| T1621 Multi-Factor Authentication Request Generation |
GroupScattered Spider | Scattered Spider has used multifactor authentication (MFA) fatigue by sending repeated MFA authentication requests to targets. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.