{"id":3559,"date":"2024-05-14T15:18:40","date_gmt":"2024-05-14T20:18:40","guid":{"rendered":"https:\/\/www.darkreading.com\/threat-intelligence\/fbi-closes-in-scattered-spider-attacks-finance-insurance-orgs"},"modified":"2024-05-14T15:18:40","modified_gmt":"2024-05-14T20:18:40","slug":"as-the-fbi-closes-in-scattered-spider-attacks-finance-insurance-orgs","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/14\/as-the-fbi-closes-in-scattered-spider-attacks-finance-insurance-orgs\/","title":{"rendered":"As the FBI Closes In, Scattered Spider Attacks Finance, Insurance Orgs"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt320f9ff851a63b5a\/655e4021a284a3040a76e14d\/spiders_Design_Pics_Inc_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/as-the-fbi-closes-in-scattered-spider-attacks-finance-insurance-orgs.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/as-the-fbi-closes-in-scattered-spider-attacks-finance-insurance-orgs.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Scattered Spider hackers have been tearing through the finance and insurance sectors, all while authorities are preparing legal actions to stop them.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A game of cops and robbers is playing out between the FBI and Scattered Spider (aka UNC3944, 0ktapus, Roasted Oktapus, Scatter Swine, Octo Tempest, Muddled Libra), the cybercrime outfit a la mode, ever since its <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/mgm-caesars-incident-responses-required-brutal-choices\" rel=\"noopener\">high-profile attacks against MGM Resorts and Caesars Entertainment<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. If recent rumblings are to be believed, the future of the group might well be determined in short course.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">On one side, Brett Leatherman, the FBI&#8217;s cyber deputy assistant director, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.reuters.com\/world\/us\/fbi-working-towards-nabbing-scattered-spider-hackers-official-says-2024-05-10\/\" rel=\"noopener\">told reporters<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in various interviews at RSAC 2024 about the agency&#8217;s plans to bring charges against members of Scattered Spider, primarily under the well-worn <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/cfaa-101-a-computer-fraud-abuse-act-primer-for-infosec-pros\" rel=\"noopener\">Computer Fraud and Abuse Act<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And yet, clearly, Scattered Spider hasn&#8217;t felt that pressure coming. In recent months it has only expanded its scope, with attacks targeting industries as broad as retail, food services, and video games.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In just the past few weeks, the group compromised at least 29 companies in the finance and insurance industries, according to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.cyberresilience.com\/threatonomics\/resilience-threat-researchers-identify-new-campaigns-from-scattered-spider\/?&amp;web_view=true\" rel=\"noopener\">research from Resilience<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. An anonymous researcher <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.bloomberg.com\/news\/articles\/2024-05-08\/notorious-scattered-spider-hacking-gang-targeting-finance-sector\" rel=\"noopener\">told Bloomberg<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> that among those targeted were household names like Visa, PNC, Transamerica, and New York Life Insurance Co., though they didn&#8217;t reveal which of those organizations in particular had failed to stop their attackers.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This latest campaign has had some of the usual hallmarks of Scattered Spider attacks: lookalike domains mimicking organizations&#8217; Okta and content management system (CMS) sign-on pages, with the potential for follow-on SIM swap attacks that leak sensitive corporate data. There was a notable efficiency to the attacks as well, with Scattered Spider swiftly deploying its infrastructure and conducting its attacks in only a few hours&#8217; time.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Can Authorities Take Down Scattered Spider?\">Can Authorities Take Down Scattered Spider?<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The effects of law enforcement interventions into cybercrime often are found in the finer details: <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/after-lockbit-alphv-takedowns-raas-recruiting-drive\" rel=\"noopener\">the confidence that affiliates lose in brand-name groups<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, the power vacuums that result, and the looming threat to anyone who dares take their place.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">There&#8217;s little evidence that major takedowns of infrastructure, or even arrests here and there, take significant numbers of criminals off the web. The keyboard warrior is a shifty species that&#8217;s tough to find and pin down, and tends to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/breakup-conti-ransomware-members-dangerous\" rel=\"noopener\">reconstitute in new forms<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> after brief periods of disruption. Worse is when they reside in parts of the world where law enforcement isn&#8217;t equipped or inclined to help out Western authorities.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The rub with Scattered Spider is that it&#8217;s distinctly not<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\"> <\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">foreign. Its members are thought to be <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/-scattered-spider-mgm-cyberattack-casinos\" rel=\"noopener\">primarily young people in the US and the UK<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. If ever there were a hacking operation the FBI could wipe out, full stop, it would be this one.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">But taking out a major hacking operation is not a simple job, says former FBI cyber special agent Adam Marr\u00e8, now chief information security officer (CISO) at Arctic Wolf. &#8220;It&#8217;s about making sure you can prove all the elements of a crime, and prove it to such a degree that you can get good penalties that will be punitive and discourage others from doing the same thing. It takes a while to build a case like that,&#8221; he explains.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">To achieve that, he continues, &#8220;They&#8217;re going to be doing everything from getting informants, or possibly undercovers, into online forums where they can talk to perpetrators whose guard might be down. It&#8217;s also going to be important for them to collect evidence from victim companies that can be then used to attribute the actions of these actors. The most difficult part is always attribution, so being able to show who was behind the keyboard when that happened takes all the investigative techniques that they have at their disposal.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Because ironclad attribution is so crucial, and because it&#8217;s so elusive, the openness and cooperation of targeted organizations may prove the difference in bringing bad guys to justice.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;I&#8217;m always an advocate that, during peacetime, when you&#8217;re not attacked, you should still go talk to your local authorities,&#8221; Marr\u00e8 emphasizes. &#8220;Find out who they are, find out what numbers you can call, so that you know these folks when bad things happen. And then, possibly, you can have an effect on the whole cybercrime industry, lessening the likelihood that these things will happen to other people.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/fbi-closes-in-scattered-spider-attacks-finance-insurance-orgs\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Scattered Spider hackers have been tearing through the finance and<\/p>\n","protected":false},"author":12,"featured_media":3560,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3559","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/as-the-fbi-closes-in-scattered-spider-attacks-finance-insurance-orgs-scaled.jpg?fit=2560%2C1585&ssl=1",2560,1585,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/as-the-fbi-closes-in-scattered-spider-attacks-finance-insurance-orgs-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/as-the-fbi-closes-in-scattered-spider-attacks-finance-insurance-orgs-scaled.jpg?fit=300%2C186&ssl=1",300,186,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/as-the-fbi-closes-in-scattered-spider-attacks-finance-insurance-orgs-scaled.jpg?fit=640%2C396&ssl=1",640,396,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/as-the-fbi-closes-in-scattered-spider-attacks-finance-insurance-orgs-scaled.jpg?fit=640%2C396&ssl=1",640,396,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/as-the-fbi-closes-in-scattered-spider-attacks-finance-insurance-orgs-scaled.jpg?fit=1536%2C951&ssl=1",1536,951,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/as-the-fbi-closes-in-scattered-spider-attacks-finance-insurance-orgs-scaled.jpg?fit=2048%2C1268&ssl=1",2048,1268,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/as-the-fbi-closes-in-scattered-spider-attacks-finance-insurance-orgs-scaled.jpg?fit=1024%2C634&ssl=1",1024,634,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/as-the-fbi-closes-in-scattered-spider-attacks-finance-insurance-orgs-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/as-the-fbi-closes-in-scattered-spider-attacks-finance-insurance-orgs-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/as-the-fbi-closes-in-scattered-spider-attacks-finance-insurance-orgs-scaled.jpg?fit=2560%2C1585&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3559","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3559"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3559\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3560"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3559"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3559"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3559"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}