Accessibility links
  • Skip to main content
News Icon NEWS FILTER
All News Security Education Videos Scams & Phishing Your Security Mobile Security Identity Theft Corporate Security
Search Icon SEARCH
 

Email Icon SUBSCRIBE TO WEEKLY NEWSLETTER
Scattered Spider’s Web Of Lies, Deception And Ransomware
Facebook   X   LinkedIn   Email

Scattered Spider’s Web Of Lies, Deception And Ransomware

January 18, 2024

Warnings from the FBI and CISA came in loud and clear…Scattered Spider’s cyberattacks are more hazardous and crippling than ever before. Their high-profile, financially motivated attacks rely on social engineering for data theft, extortion, and ransomware attacks. And when both security agencies release a joint advisory warning to us about this threat group, it’s smart to listen.

These threat actors made headlines for crippling financial attacks against MGM Resorts International, Caesar’s Entertainment, and Okta. Although they refused to pay the ransom demand, MGM’s attack alone cost the company more than $100 million in losses.

Scattered Spider gained entrance to MGM’s systems after finding an employee’s profile on LinkedIn, giving the group what they needed for their socially engineered phone call (vishing) attack. Just one phone call led to them stealing a trove of sensitive data and unleashing BlackCat ransomware on the entertainment behemoth.

Scattered Spider’s Web of Deception

Since 2022, Scattered Spider, aka Oktapus/Octo Tempest, began making headlines. The group didn’t waste time using an arsenal of weapons for financial crimes. They’re considered experts in social engineering and big money theft, as MGM and others lived to tell.

Scattered Spider’s socially engineered attacks trick potential victims with phishing techniques and expert deception. A staffer is convinced that the text, email, or phone caller is legitimate. They’re tricked into giving up information the group exploits, giving them a foothold for their eventual ransomware attack.

As the FBI/CISA advisory warns about Scattered Spider’s weapons and tactics "After identifying usernames, passwords, PII, and conducting SIM swaps, the threat actors then use social engineering techniques to convince IT help desk personnel to reset passwords and/or MFA tokens…” Their techniques also use account takeovers (ATO), push bombing, installing remote access tools, and others they have waiting in their web.

Only Scattered Spider knows who their next victim will be, but we can be sure they’re spinning a web ready to put them back in the headlines soon.


Cool Off With Quick Social Engineering Refresher

Scams & Phishing

Cool Off With Quick Social Engineering Refresher

Let's dive into the world of social engineering and its impact on our lives, shall we? Brace yourself for a friendly reminder about this sneaky psychological manipulation technique that can really mess with your day. Picture this: someone cleverly exploits your mind to get you to do their bidding or spill sensitive information. It could never happen to you, right? Well, think again. Sometimes they sneak up on you and don't even know what's going on until it's too late. READ FULL STORY

Phishing Examples Of  The Current Top Ransomware Threats

Your Security

Phishing Examples Of The Current Top Ransomware Threats

Ransomware attacks have become increasingly prevalent and damaging in recent years and they do not discriminate. Every person, industry, or organization is fair game for cybercriminals wanting to make a buck; in most cases, many bucks. Cybercriminals are constantly on the lookout for vulnerabilities they can exploit to gain unauthorized access and deploy ransomware. Here, we highlight some of the most significant vulnerabilities leveraged by ransomware groups, their implications, and the importance of securing these weaknesses. READ FULL STORY

A Ransomware Group And Their Sizzling Summer Of Attacks

Your Security

A Ransomware Group And Their Sizzling Summer Of Attacks

A ransomware threat group known by several names, one of them being “Oktapus,” recently made another name for itself. Thanks to its spree of high-profile attacks this summer, Microsoft researchers call them “one of the most dangerous financial criminal groups.” A closer look at this group explains who they are, who they attack, and why they’re so dangerous. Most recently, the group's top attacks were on MGM Resorts, Caesars Entertainment, and Clorox, just to name a few. READ FULL STORY

Ransomware Attacks Drop 25% But That's Not The Whole Story

Your Security

Ransomware Attacks Drop 25% But That's Not The Whole Story

There’s news about ransomware getting mixed reactions from everyday users and businesses alike. Since both groups share concern over these devastating attacks, findings in April from the UK’s NCC Group are proving to be a real head-scratcher. On one hand, the numbers are good and on the other…not so good. So, what’s behind this mixed bag of ransomware statistics? In their monthly Cyber Threat Intelligence Report, NCC Group tells us both sides of the story. READ FULL STORY

BlackCat Brings Bad Luck Using Google Ads

Scams & Phishing

BlackCat Brings Bad Luck Using Google Ads

Trend Micro researchers recently identified that a notorious ransomware group is using various malvertising tricks within Google Ads to distribute fake WinSCP installers. They are using Targeted Attack Detection (TAD) service. What is that, you say? This means that if you click on an infected ad that you see on your webpage, your network could get a bad case of cat scratch fever. Threat actors are taking advantage of Google Ads to launch malvertising campaigns. READ FULL STORY








Close
Fraud News & Alerts!

Keep up with the latest cyber security news through our weekly Fraud News & Alerts updates. Each week you will receive an email containing the latest cyber security news, tips and breach notifications.



You're all set!

You will receive your first official security update email within the next week.

A welcome email has also just been sent to you. If you do not receive this email within the next few minutes, please check your Junk box or spam filter to confirm our emails are not being blocked.


 
Help  
Enter any word or words you like.        

The email newsletter will arrive from news@stickleyonsecurity.com


Loading
Please wait...