HomeSecurityScattered Spider targets the financial sector

Scattered Spider targets the financial sector

Cybersecurity researchers have linked new cyberattacks targeting financial services to the notorious cybercrime group Scattered Spider, casting doubt on the hackers' recent claims that they are retreating.

Scattered Spider financial sector

Threat intelligence firm ReliaQuest said it has seen indications that the threat actor has shifted its focus to the financial sector. This is supported by the increase in domains potentially associated with the group that are geared towards that industry. It has also identified a recent targeted attack on an unnamed US banking organization.

“Scattered Spider initially gained access to an executive’s account (using social engineering) and changed the password via Azure Active Directory Self-Service Password Management,” the company said. “From there, they gained access to sensitive IT and security documents, moved laterally through the Citrix environment and VPN, and compromised the VMware ESXi infrastructure to steal credentials and further infiltrate the network.”

To achieve privilege escalation, the attackers reset the password of a Veeam service account, assigned Azure Global Administrator permissions, and migrated virtual machines to evade detection.

See also: RevengeHotels leverages AI to distribute VenomRAT

There is also evidence that Scattered Spider attempted to extract data from Snowflake, Amazon Web Services (AWS), and other repositories.

Scattered Spider: Is it finally ceasing its activities?

The recent activity undermines the group’s claims that it is disbanding along with 14 other criminal groups, including LAPSUS$. Scattered Spider is the nickname given to a loosely connected group of hackers that is part of a larger online entity called The Com. The group also shares many similarities with other cybercrime groups such as ShinyHunters and LAPSUS$. In fact, the three groups reportedly formed an overarching entity called “scattered LAPSUS$ hunters.”

One of these groups, ShinyHunters, has also been involved in extortion after extracting sensitive data from Salesforce instances . In these cases, the malicious activity occurred months after the targets were compromised by another financially motivated hacking group, tracked by Google’s Mandiant as UNC6040.

According to ReliaQuest, the new attacks are a reminder not to lull ourselves into a false sense of security. Organizations are urged to remain vigilant against the threat. As in the case of ransomware groups, hackers are regrouping and emerging under new names.

Scattered Spider targets the financial sector

"The recent claim that Scattered Spider is shutting down should be taken with a high degree of skepticism," said Karl Sigler, director of security research at SpiderLabs Threat Intelligence. "Rather than an actual breakup, this announcement likely signals a strategic move to distance the group from increasing pressure from law enforcement."

See also: Hackers stole customer data from Gucci, Balenciaga and Alexander McQueen

Sigler also pointed out that the farewell letter should be seen as a strategic retreat, allowing the team to reevaluate its practices, improve its expertise, and avoid ongoing efforts to curtail its activity.

«It’s possible that something within operational infrastructure has been compromised. Whether through a compromised system, an exposed communication channel, or the arrest of lower-level associates, something has likely caused the group to disappear, even temporarily. Historically, when cybercrime groups face increased scrutiny or internal turmoil, they have often “retired” in name only, choosing to regroup and eventually re-emerge under a new identity.“.

Scattered Spider targets the financial sector

Financial sector: Protection to enhance cybersecurity

Given that the new Scattered Spider attacks target financial services, it is essential to take protective measures in the industry.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Organizations must implement multi-layered security strategies to protect their data. One of the key measures is encryption data, both in transit and at rest. This ensures that data is readable only by authorized individuals or systems.

Another important measure is the use of multi-factor authentication (MFA). This technique requires users to verify their identity using more than one factor, such as passwords, biometric data, or codes sent via SMS.

should also be made in threat detection and response (TDR) systems. These systems constantly monitor networks for suspicious activity and can detect and block attacks in real time.

See also: Hackers maliciously use Code Assistant to insert Backdoors

Staff training is also critical. Organizations in the financial sector should regularly organize training seminars and exercises to keep their employees informed about the latest threats and security best practices .

Artificial intelligence and machine learning technologies can be leveraged to identify suspicious behaviors and predict potential threats. These technologies can analyze vast amounts of data and identify patterns that may indicate an impending attack.

Finally, organizations should collaborate with specialized cybersecurity companies and participate in information exchange networks to share knowledge and stay informed about the latest trends and techniques used by cybercriminals.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS