Team Cymru: Scattered Spider hides in services you cannot block
Team Cymru has analysed Scattered Spider's infrastructure as described in open-source reporting. Over the past couple of years the group's victims have included MGM Resorts, Marks & Spencer, The Co-op and Harrods. The central message of the analysis is that the techniques the group uses to obtain network access are a large part of why they have been so prolific. By leveraging widely trusted, high-profile services, the actors blend into normal traffic, making it far harder for defenders to block their activity without also disrupting legitimate use of those same services.
What this means for your organisation
This is a detection problem dressed up as a blocking problem. Retail, travel and service businesses with large workforces and heavy cloud use are precisely the profile this group has pursued. When the attacker uses the same services you do, your defence has to shift from where traffic goes to how accounts and devices behave. That is an investment in logging and analysis, not in one more firewall rule.
Berigo recommends
- Build detection around anomalous account behaviour: sign-in from new devices, unusual hours and abrupt changes in access patterns.
- Govern which cloud services are permitted for corporate data, and log their use centrally.
- Tighten first-line procedures for password and MFA resets, with verification that cannot be talked around.
- Review which third-party applications have been granted access to your identity platform.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch