November 27, 2023 By Colin J. Zick
Categories: Ransomware
Large companies holding sensitive data – including financial services, telecommunications, business process outsourcing, hospitality, and cryptocurrency firms – as well as their IT helpdesks, are increasingly being targeted by ransomware attacks. The Federal Bureau of Investigation (FBI) and Cybersecurity & Infrastructure Security Agency (CISA) have jointly released a cybersecurity advisory in response to recent activity by the threat actor group known as Scattered Spider. Scattered Spider received significant attention in September 2023 when it launched a ransomware attack against multiple casino operators, the details of which became known in securities filings following the SEC's adoption of data breach reporting rules for public companies in July 2023. Scattered Spider has re-emerged in recent days launching ransomware attacks against multiple targets in a short span of time. The main details of the advisory are summarized below, though clients should direct their IT professionals to consult the full advisory.
What techniques are Scattered Spider employing?
Scattered Spider operatives have been reported to be posing as company IT or helpdesk staff in order to obtain credentials from employees, or to direct employees to run remote access tools that permit Scattered Spider to access a company network. Because IT support is also frequently offered through the use of remote access tools, Scattered Spider has been able to successfully impersonate IT professionals on a number of occasions. Similarly, Scattered Spider has been making use of multi-factor authentication tools (again utilizing tools that are familiar to employees who frequently utilize tech support) to prompt employees to share passwords and/or run remote access tools.
What can be done to mitigate the threat?
The FBI and CISA recommend the use of the following measures:
In addition, the FBI and CISA reinforce the continued importance of basic cybersecurity best practices:
Additionally, the FBI and CISA are actively soliciting reporting on the Scattered Spider group actors, and urge individuals or entities suffering from ransomware attacks or that obtain information about Scattered Spider to contact a local FBI field office or CISA operations center.