Thank you to everyone who joined the Scattered Spider: Tracing the Web Webinar!
With Scattered Spider rumoured to have been the ransomware gang behind the Qantas breach and put on alert by CISA we decided to look further into this gangs TTPs and indicators.
Cybersecurity is reimagined on a day-to-day basis so staying vigilant about active groups can help us secure our companies and our data!
If you missed webinar here are our main points to focus on and you can view the entire stream at:
Who are they?
Decentralised group of young English native speakers and certainly use this to their advantage! With their focus on social engineering and aggressive techniques such vishing.
Who are they targeting?
Scattered Spider seems to be targeting sector to sector, in the past they have focused on the financial, entertainment, retail and now it seems they’ve moved onto aviation…
They target large companies that are going through high pressured environments particularly those with strong customer obligation. Downtime or public exposure of these companies causes maximum leverage, and they hope… maximum payouts.
What to watch out for?
We’ve seen them go through help desks, impersonating staff using real information they’ve found on LinkedIn or data leaks. Clearly showing reconnaissance and that anything online is fair game. They exploit urgency and trust when contacting these help desks or third-party providers.
Additionally, they are suspected to have connections with ‘The Community’ who are expert sim swappers. Using spoofed caller IDs and tailored voice scripts.
Living off the Land
Scattered Spider have been tracked to use different RaaS such as BlackCat and DragonForce to execute ransoms, but they typically use the tools you and I can find on our laptops already. Different Remote Access, Tunnelling and Credential Access such as TeamViewer, Ngrok and Mimikatz.
Our Defensive Recommendations
- Enhance Help Desk Verification: Require callbacks or manager approval for MFA resets.
- Use Phishing-Resistant MFA: Adopt hardware-based keys
- Detect MFA Fatigue: Monitor for repeated push attempts.
- Secure Third-Party Access: Apply least privilege principles.
- Segment networks to prevent the spread of ransomware.
- Ensure all backup data is encrypted, immutable
What we are seeing is that its human error which is inevitable but training and increasing security mechanisms to catch and prevent this is crucial.


