Scattered Spider hackers , former affiliates of the ALPHV/BlackCat ransomware, appear to be now collaborating with the RansomHub group , according to an analysis by GuidePoint Security .

By analyzing techniques and processes used, researchers believe that at least part of the Scattered Spider group is now conducting ransomware attacks with RansomHub.
The operators of the ALPHV/BlackCat shut down their servers in March amid allegations that they defrauded the affiliate responsible for the Optum hack and stole $22 million, which Optum allegedly paid as a ransom.
See also: Scattered Spider: The FBI reveals its tactics
At the same time, another RaaS model has come to the fore, RansomHub, which reportedly hit Change Healthcare's owner UnitedHealth Group shortly after the first breach, threatening to publish data stolen in the initial attack.
Scattered Spider hackers now partner with RansomHub team
GuidePoint said its analysis began while responding to a ransomware attack attempting to impact ESXi in early 2024.
The attack was later attributed to a subsidiary of the RansomHub RaaS group, and researchers are fairly certain that the attackers themselves had previously carried out BlackCat ransomware attacks
GuidePoint has since assessed with high confidence that this threat actor is either a current or former member of the Scattered Spider group. This is based on multiple factors related to known Scattered Spider tools, processes, and infrastructure.
See also: Microsoft warns as Scattered Spider expands from SIM Swaps to Ransomware
Scattered Spider hackers are primarily involved in data theft for extortion and are believed to be responsible for a series of attacks that affected major organizations over the past year, including MGM International, Caesars Entertainment, and Okta.
The group is known for its social engineering skills, often posing as support staff to trick employees into handing over credentials.
After gaining initial access to a network, Scattered Spider hackers use a range of tools and techniques to spread across the network and extract data that overlap with some RansomHub attacks. Some of these are: SecretServerSecretStealer, ngrok, Remina.
See also: Scattered Spider: Trying to avoid detection with the Bring-Your-Own-Driver tactic
Ransomware protection
Back up your data: One of the most effective ways to protect yourself from a ransomware attack is to regularly back up your data. This ensures that even if your data is encrypted by ransomware, you will have a safe copy that can be restored without paying the ransom.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Update your operating system and software: Out-of-date operating systems and software are vulnerable to cyberattacks, including ransomware. It is important to regularly update your devices with the latest security and software updates to prevent any vulnerabilities that could be exploited by ransomware.
Beware of suspicious emails and links: Ransomware attacks often start with a phishing email or malicious link. It is important to be cautious when opening emails from unknown senders. Also, do not click on suspicious links. These could lead to ransomware being installed on your device.
Use antivirus software: Installing reputable antivirus software on your devices can help you detect and prevent attacks . Be sure to update your antivirus software regularly to ensure it is equipped to handle new threats.
See also: New Fog ransomware targets educational institutions
Education: One of the most important steps to protect against ransomware is education. It is important to stay up to date on the latest types of ransomware and how they work. Organizations should also train their employees on how to identify and avoid potential attacks.
Implement strong passwords: Weak or easy passwords can make it easier for hackers to gain access to your devices and install ransomware. It's important to use strong and unique passwords and enable two-factor authentication whenever possible.
Use a VPN: A VPN encrypts your internet connection and provides an extra layer of security against ransomware attacks. This is especially important when using public Wi-Fi networks, which are often unsecured and vulnerable to cyberattacks.
Source: www.infosecurity-magazine.com
