Servicio criminal / operación underground
Scattered Spider
Estado: Activo
Confianza: Confirmado
Octo Tempest is a financially motivated intrusion set best known for social engineering and identity compromise rather than heavy custom malware. Microsoft describes the group as using broad social engineering campaigns to compromise organizations for extortion, including encryption and destruction, and highlights an industry “wave” pattern where targeting concentrates on a sector for weeks before pivoting. The joint FBI/CISA advisory (AA23-320A) characterizes the group as targeting large companies and their contracted IT help desks, using phone/SMS pretexts, MFA fatigue, and SIM swap techniques to obtain access, install remote tools, and bypass MFA.
ATT&CK
MITRE ATT&CK
T1041Exfiltration Over C2 Channel
T1078Valid Accounts
T1110Brute Force
T1219Remote Access Tools
T1486Data Encrypted for Impact
T1562.001Disable or Modify Tools
T1566Phishing
T1572Protocol Tunneling
T1598.004Spearphishing Voice
T1621Multi-Factor Authentication Request Generation
Research
OSINT seleccionado
Defending Your VMware vSphere Estate from UNC3944|Google Cloud (Mandiant / GTIG)Scattered Spider (AA23-320A) — Updated advisory (PDF)|IC3 / FBI / CISA (Joint CSA)Joint cyber security advisory on Scattered Spider|Canadian Centre for Cyber SecurityJoint advisory released on recent activity by Scattered Spider threat actors|Australian Cyber Security CentreMaritime Cyber Alert 04-25 (TLP:CLEAR) — Scattered Spider (PDF)|U.S. Coast Guard Cyber Command