HomeSecurityMicrosoft warns as Scattered Spider expands from SIM Swaps to...

Microsoft warns as Scattered Spider expands from SIM Swaps to Ransomware

The Scattered Spider hacking group has been observed impersonating newly hired employees at targeted companies, as a tactic to integrate into normal hiring processes and gain access to accounts and breach organizations around the world.

See also: IoT Malware attacks increased by 400%

With the aim of matching their profile, corporate account and work environment, it participates in the formal procedures of various organizations worldwide.

Microsoft has released the details of Scattered Spider and warned us that it is a dangerously successful group of financially motivated hackers that uses aggressive SIM phishing and SIM swapping techniques in its attack model.

Microsoft warns as Scattered Spider expands from SIM Swaps to Ransomware

See also: Kroll: Announced data breach (started by SIM swapping)

The Octo Tempest hacking group, which overlaps with research related to 0ktapus, Scattered Spider, and UNC3944, was initially identified in early 2022, targeting mobile and external business support companies to attempt to effect changes to phone numbers.

Microsoft states more specifically: "They are an English-speaking, financially motivated hacking group known for executing extensive campaigns involving adversary-in-the-middle (AiTM) techniques, social engineering, and SIM swapping capabilities."

Microsoft warns as Scattered Spider expands from SIM Swaps to Ransomware

See also: Scattered Spider: Trying to avoid detection with the Bring-Your-Own-Driver tactic

Octo Tempest targets a variety of sectors, from technology services, finance, gaming, and retail. Essentially, it uses various techniques from the BlackCat hacking group, which was responsible for multiple ransomware attacks in 2023.

"In late 2022, the Octo Tempest hackers began to collect revenue from intrusions by blackmailing targeted organizations both online and in person," Microsoft.

She recommends "Do not post your personal information on easily accessible websites on the internet (home addresses, family names, phone numbers). As in rare cases, of course, Octo Tempest had resorted to regular threats, instilling fear, targeting specific individuals using the aforementioned factors."

See also: Security Copilot AI: Microsoft announces early access program

The Scattered Spider in the technical part

"A unique technique used by Octo Tempest is to compromise the VMware ESXi, install the Linux backdoor Bedevil, and then launch a VMware Python to execute arbitrary commands on housed virtual machines (protects against software and hardware failures on the physical machine by placing the system nodes on separate ESXi hosts)," the company further explained.

Information source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS