PULSE NAME
Ransomware in the Cloud: Scattered Spider Targeting Insurance and Financial Industries
WHITE SCATTERED SPIDER AlienVault 2024-09-11 Modified: 2024-09-11
20
IOCs
MEDIUM VOLUME
The Scattered Spider cybercriminal group is targeting cloud infrastructures in the insurance and financial sectors using advanced techniques. They exploit leaked authentication tokens, conduct phishing and smishing campaigns, and leverage SIM swapping to bypass multi-factor authentication. The group uses open-source tools for reconnaissance, disables security measures, and maintains persistence through various methods like cross-tenant synchronization abuse. They focus on deploying ransomware in cloud environments, particularly VMware ESXi and Azure. The attackers demonstrate deep knowledge of Western business practices and partner with other ransomware groups like BlackCat/ALPHV to enhance their capabilities.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Stealc Raccoon Stealer Vidar Stealer RedLine Stealer BlackCat - S1068 ALPHV Noberus
Indicators of Compromise (6 / 20 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 1d05a83a639031913574c0bbb06026a4 2024-09-11
FileHash-MD5 586bd54b564926682b75330b190cbace 2024-09-11
FileHash-MD5 8445274c237eb83d56070e499f43641f 2024-09-11
FileHash-MD5 b233ff9dcf5520d69f9b75e1424f3271 2024-09-11
FileHash-MD5 c7497366fd0d8c9d72f96e7190632a51 2024-09-11
FileHash-MD5 cc230dcea35be180e3487b53e4b2cfba 2024-09-11