PULSE NAME
Ransomware in the Cloud: Scattered Spider Targeting Insurance and Financial Industries
WHITE SCATTERED SPIDER AlienVault 2024-09-11 Modified: 2024-09-11
20
IOCs
MEDIUM VOLUME
The Scattered Spider cybercriminal group is targeting cloud infrastructures in the insurance and financial sectors using advanced techniques. They exploit leaked authentication tokens, conduct phishing and smishing campaigns, and leverage SIM swapping to bypass multi-factor authentication. The group uses open-source tools for reconnaissance, disables security measures, and maintains persistence through various methods like cross-tenant synchronization abuse. They focus on deploying ransomware in cloud environments, particularly VMware ESXi and Azure. The attackers demonstrate deep knowledge of Western business practices and partner with other ransomware groups like BlackCat/ALPHV to enhance their capabilities.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Stealc Raccoon Stealer Vidar Stealer RedLine Stealer BlackCat - S1068 ALPHV Noberus
Indicators of Compromise (20)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 1d05a83a639031913574c0bbb06026a4 2024-09-11
FileHash-MD5 586bd54b564926682b75330b190cbace 2024-09-11
FileHash-MD5 8445274c237eb83d56070e499f43641f 2024-09-11
FileHash-MD5 b233ff9dcf5520d69f9b75e1424f3271 2024-09-11
FileHash-MD5 c7497366fd0d8c9d72f96e7190632a51 2024-09-11
FileHash-MD5 cc230dcea35be180e3487b53e4b2cfba 2024-09-11
FileHash-SHA1 70eecb0234d06b8e73e0c069572911516a8076f4 2024-09-11
FileHash-SHA1 8b25880d3f8cfbde1aef12c0f7bb46fe020ed97a 2024-09-11
FileHash-SHA256 bef3e8a4231b236d34556cf681020792d04b19e3e73c7507534ceb5042eec620 2024-09-11
FileHash-SHA256 d780134609e2b5c9ec6b75e35c5f6eefcb1527105a584c6fbcff5dee33cebd37 2024-09-11
URL http://forward-icloud.com/admin/dashboard/login 2024-09-11
URL https://www.silentpush.com/blog/scattered-spider/ 2024-09-11
domain authenticate-bt.com 2024-09-11
domain creditkarma-help.com 2024-09-11
domain forward-icloud.com 2024-09-11
domain revolut-ticket.com 2024-09-11
domain securian-hr.com 2024-09-11
domain servicenow-help.com 2024-09-11
hostname login.five9-hr.com 2024-09-11
hostname login.uscc-hr.com 2024-09-11