🔎ScatteredSpider/0ktapus is a BlackCat (ALPHV) affiliate, but doesn't deploy ransomware
- Based on some temporal, technical, and behavioral analysis
Follow me 🐇🕳 (1/6)
9 Feb 23, Reddit faced a 'highly-targeted phishing attack' & had docs and source code stolen
TTPs are very similar to ScatteredSpider/0ktapus campaigns:
- a landing page impersonating its intranet site
- stolen employees' credentials and 2FA codes reddit.com/r/reddit/comme… (2/6)
22 May 23, Trend Micro revealed that a BlackCat affiliate used an identical Microsoft-signed POORTRY sample (909f3fc221acbe999483c87d9ead024a) used by UNC3944 (ScatteredSpider/0ktapus), which Trend says they have used since February 2023 (3/6)
Overlaps 🔎
- ⌚ Temporal: The Reddit breach took place at the same time as the BlackCat post says
- ⚙ Technical: Reuse of the TTPs (SMS/SSO phish) and same tools (the POORTRY driver)
- 🕵️♂️ Behavioral: Data-theft-extortion operations, English-speaking threat actors
(5/6)
There's still *much* to uncover about the relationship between ScatteredSpider/0ktapus and BlackCat (ALPHV) but these public reports do indicate various connections. 🕷🐈⬛
More English-speaking threat actors working with Russia-based ransomware groups is a noteworthy trend. (6/6)
• • •
Missing some Tweet in this thread? You can try to
force a refresh
CTI vendors and their platforms are lucrative target for cybercriminals. They host tons of valuable reports and threat intel data, including breach data.
Cybercriminals have targeted multiple CTI platforms to see this information. Cybercrime Counterintelligence, if you will.
My iCloud is recently getting a few #16Shop#phishing emails, I RE'd the links (for lack of a better term) and found a whole trawl of their previous phish. Highly organised operation which has been going on for a few years.
The links are text which have been highlighted and use s[.]id URL shorteners & IP logging service from (surprise surprise) Indonesia. More specifically: Pengelola Nama Domain Internet Indonesia.
They also use app[.]link from Branch.io that uses "Deep Linking".