HomeSecurityScattered Spider Hackers: How they carry out their attacks

Scattered Spider Hackers: How They Carry Out Their Attacks

Financially motivated Scattered Spider hackers breach telecommunications service providers and business process outsourcing companies, actively reversing defensive mitigations that are implemented when a breach is detected.

Crowdstrike spotted the campaign and says it began in June 2022. The research team can identify five different hacks so far, but believes that even more are now taking place.

The attacks, carried out by the “Scattered Spider” hackers, show that hackers maintain persistence in the access process, reverse mitigations, evade detection , and move on to other valid targets if thwarted.

The ultimate goal of the campaign is to breach telecommunications network systems, access subscriber information, and conduct operations such as SIM swapping.

See also: Serious AMI MegaRAC vulnerabilities affect the servers of many companies

Scattered Spider

See also: Google Chrome update: Fixes the 9th zero-day of the year

Campaign details

Hackers manage to enter companies' computer systems using various social engineering tricks.

These tactics include calling employees and impersonating IT staff to collect credentials or using Telegram and SMS to redirect targets to customized phishing websites that feature the company logo.

If MFA protected the target accounts, attackers either used MFA fatigue tactics with push-notification or engaged in social engineering to obtain the passwords from the victims.

In one case, hackers exploited CVE-2021-35464, a flaw in the ForgeRock AM server that was patched in October 2021, to execute code and elevate privileges on an AWS instance.

Once hackers gain access to a system, they attempt to add their own devices to the list of trusted MFA (multi-factor authentication) devices using the compromised user account.

Crowdstrike observed that hackers are using the following utilities and remote monitoring and management (RMM) tools in their campaigns:

  • AnyDesk
  • BeAnywhere
  • Domotz
  • DWservice
  • Fixme.it
  • Fleetdeck.io
  • Itarian Endpoint Manager
  • Level.io
  • Logmein
  • ManageEngine
  • N-Able
  • Pulseway
  • Report
  • Rsocx
  • ScreenConnect
  • SSH RevShell and RDP Tunneling via SSH
  • Teamviewer
  • TrendMicro Basecamp
  • Sorillus
  • ZeroTier

Some of the software listed above is commonly found on corporate networks and is not likely to trigger alerts in security tools.

Intrusions observed by Crowdstrike revealed that adversaries will stop at nothing to maintain access to a compromised network, even after detection.

In every intrusion case Crowdstrike tracked, criminals used multiple VPNs and ISPs to break into the targeted organization's Google Workspace environment

Scattered Spider Hackers: How They Carry Out Their Attacks

See also: Zero-day vulnerabilities and the urgent need to address them

To move laterally, threat actors extracted various types of identifying information, downloaded user lists from compromised tenants, abused WMI, and performed SSH tunneling and domain replication.

Crowdstrike shared an extensive list of indicators of compromise (IoCs) for this activity at the bottom of the report, which is crucial for defenders as the threat actor uses the same tools and IP addresses across different intrusions.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS