Target Industry
Scattered Spider have been seen targeting these sectors:
- Financial
- Gaming
- Hospitality
- Insurance
- Managed Service Providers (MSPs)
- Manufacturing
- Retail
- Transportation
Overview
The FBI has issued a warning about the Scattered Spider cybercriminal group, which is now targeting the transportation sector, including airlines. The warning highlights the group’s use of social engineering to impersonate employees or contractors, allowing them to bypass multi-factor authentication (MFA). The FBI is collaborating with aviation and industry partners to address this activity and assist victims.
Impact
The impact of these cybersecurity threats on the insurance industry can be profound. Ransomware attacks can lead to significant operational disruptions due to network outages. The financial implications can be severe, including potential ransom payments, legal fees, and costs associated with recovery efforts.
Exploitation
Scattered Spider often starts the ransomware attack with fake helpdesk calls to gain access to devices. For this they use social engineering or SIM-swapping, to gain unauthorised access to personal accounts and sensitive information. The group move on to deploy DragonForce ransomware, adding a ransom note into the affected directories.
The data is exfiltrated and threaten to be released publicly if the ransom is not paid. Access to the compromised systems is maintained, allowing them to return even if the initial attack is mitigated. The group attempt to move laterally within the network to infect other devices and systems, increasing the scope of the attack.
Indicators of Compromise
Here are some indicators of compromise associated with Scattered Spider. For a more in-depth listing, please refer to the Quorum Cyber ransomware report on the group.
| Indicator | Type | Description |
| README.txt | Ransom note | Name of ransom note left in the directories of encrypted file |
| ..df | File extension | File extension used by DragonForce |
| 9a218d69ecafe65eae264d2fdb52f1aa | md5 | File hashes used by DragonForce ransomware |
| d44071f255785c73909d64f824331ebf | md5 | File hashes used by DragonForce ransomware |
| b97812a2e6be54e725defbab88357fa2 | md5 | File hashes used by DragonForce ransomware |
Containment, Mitigations & Remediations
To improve cybersecurity, organisations should consider the following recommendations:
- Enhance employee training on recognising phishing attempts and social engineering tactics.
- Implement strong authentication by utilising multi-factor authentication (MFA) and ensuring robust identity verification processes.
- Conduct regular security audits of security protocols and systems.
- Develop incident response plans, by having a well-defined incident response strategy can minimise the impact of a cyberattack and ensure a swift recovery
Threat Landscape
Cybersecurity threats in the transportation industry are evolving rapidly. The frequency of attacks has increased, with threat groups like Scattered Spider shifting their focus to new sectors, including transportation, as they exhaust previous targets. The speed at which new tactics are developed and deployed is alarming, with reports indicating that attacks are becoming more sophisticated and harder to detect. This trend necessitates constant vigilance and adaptation from insurance companies to keep pace with emerging threats.
Threat Group
Scattered Spider, also known as UNC3944, is a prominent threat group that has recently pivoted its focus to the insurance sector. This group is known for its high-impact campaigns that often involve social engineering, phishing, and ransomware attacks. Their tactics include impersonating IT staff to manipulate help desk personnel into granting access to sensitive systems.
The group has a history of targeting specific sectors sequentially, which raises concerns about their potential to cause widespread disruption in the insurance industry. Scattered Spider collaborates with major ransomware operators and has ties with Russia-aligned threat groups, enhancing their impersonation tactics.
Access our Scattered Spider Ransomware report here: Scattered Spider Report
Further Information













