Federal Bureau of Investigation (#FBI) and Cybersecurity and Infrastructure Security Agency (#CISA) have put out a joint advisory on #ScatteredSpider - a #cybercriminal group that targets large companies and their contracted information technology (IT) help desks. Scattered Spider threat actors, per trusted third parties, have typically engaged in data theft for extortion and have also been known to utilize BlackCat/ALPHV ransomware alongside their usual TTPs. This advisory covers all #TTPs and provides recommendations for mitigation.
Anyone in #criticalinfrastructure who uses external IT services (#MSP) should review this advisory and create awareness with your users to #BOLO this advanced attack vector.
This crew are masters of #SocialEngineering so watch yourselves. #StayCyberSafe #BeCyberSecure
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a
