Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims

Posted on September 17, 2025September 17, 2025 By CWS

Sep 17, 2025Ravie LakshmananThreat Intelligence / Cybercrime
Cybersecurity researchers have tied a recent spherical of cyber assaults focusing on monetary providers to the infamous cybercrime group referred to as Scattered Spider, casting doubt on their claims of going “darkish.”
Risk intelligence agency ReliaQuest mentioned it has noticed indications that the risk actor has shifted their focus to the monetary sector. That is supported by a rise in lookalike domains doubtlessly linked to the group which are geared in the direction of the trade vertical, in addition to a lately recognized focused intrusion in opposition to an unnamed U.S. banking group.
“Scattered Spider gained preliminary entry by socially engineering an govt’s account and resetting their password through Azure Energetic Listing Self-Service Password Administration,” the corporate mentioned.

“From there, they accessed delicate IT and safety paperwork, moved laterally via the Citrix surroundings and VPN, and compromised VMware ESXi infrastructure to dump credentials and additional infiltrate the community.”
To realize privilege escalation, the attackers reset a Veeam service account password, assigned Azure International Administrator permissions, and relocated digital machines to evade detection. There are additionally indicators that Scattered Spider tried to exfiltrate knowledge from Snowflake, Amazon Internet Companies (AWS), and different repositories.
Exit or Smokescreen?
The latest exercise undercuts the group’s claims that they had been ceasing operations alongside 14 different legal teams, corresponding to LAPSUS$. Scattered Spider is the moniker assigned to a loose-knit hacking collective that is a part of a broader on-line entity known as The Com.
The group additionally shares a excessive diploma of overlap with different cybercrime crews like ShinyHunters and LAPSUS$, a lot in order that the three clusters shaped an overarching entity named “scattered LAPSUS$ hunters.”
Certainly one of these clusters, notably ShinyHunters, has additionally engaged in extortion efforts after exfiltrating delicate knowledge from victims’ Salesforce cases. In these circumstances, the exercise came about months after the targets had been compromised by one other financially motivated hacking group tracked by Google-owned Mandiant as UNC6040.
The incident is a reminder to not be lulled right into a false sense of safety, ReliaQuest added, urging organizations to remain vigilant in opposition to the risk. As within the case of ransomware teams, there isn’t any such factor as retirement, as it’s totally a lot attainable for them to regroup or rebrand below a special alias sooner or later.

“The latest declare that Scattered Spider is retiring must be taken with a big diploma of skepticism,” Karl Sigler, safety analysis supervisor of SpiderLabs Risk Intelligence at Trustwave, mentioned. “Somewhat than a real disbanding, this announcement doubtless alerts a strategic transfer to distance the group from growing legislation enforcement stress.”
Sigler additionally identified that the farewell letter must be seen as a strategic retreat, permitting the group to reassess its practices, refine its tradecraft, and evade ongoing efforts to place a lid on its actions, to not point out complicate attribution efforts by making it more durable to tie future incidents to the identical core actors.
“It is believable that one thing inside the group’s operational infrastructure has been compromised. Whether or not via a breached system, an uncovered communication channel, or the arrest of lower-tier associates, one thing has doubtless triggered the group to go darkish, not less than briefly. Traditionally, when cybercriminal teams face heightened scrutiny or endure inner disruption, they typically ‘retire’ in identify solely, opting as an alternative to pause, regroup, and finally re-emerge below a brand new id.”

The Hacker News Tags:Attacks, Claims, Financial, Resurfaces, Retirement, Scattered, Sector, Spider

Post navigation

Previous Post: RaccoonO365 Phishing Service Disrupted, Leader Identified
Next Post: Shai-Hulud Supply Chain Attack: Worm Used to Steal Secrets, 180+ NPM Packages Hit

Related Posts

Cybercrime Groups ShinyHunters, Scattered Spider Join Forces in Extortion Attacks on Businesses The Hacker News
Newly Emerged GLOBAL GROUP RaaS Expands Operations with AI-Driven Negotiation Tools The Hacker News
Cybercriminals Target AI Users with Malware-Loaded Installers Posing as Popular Tools The Hacker News
What the 2025 Gartner® Magic Quadrant™ Reveals The Hacker News
State-Backed HazyBeacon Malware Uses AWS Lambda to Steal Data from SE Asian Governments The Hacker News
Cisco Warns of CVSS 10.0 FMC RADIUS Flaw Allowing Remote Code Execution The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Scalekit Raises $5.5 Million to Secure AI Agent Authentication
  • Google Announces Full Availability of Client-Side Encryption for Google Sheets
  • Critical Chaos Mesh Vulnerabilities Let Attackers Takeover Kubernetes Cluster
  • World’s Largest Hacking Forum BreachForums Creator Sentenced to Three Years in Prison
  • Shai-Hulud Supply Chain Attack: Worm Used to Steal Secrets, 180+ NPM Packages Hit

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Scalekit Raises $5.5 Million to Secure AI Agent Authentication
  • Google Announces Full Availability of Client-Side Encryption for Google Sheets
  • Critical Chaos Mesh Vulnerabilities Let Attackers Takeover Kubernetes Cluster
  • World’s Largest Hacking Forum BreachForums Creator Sentenced to Three Years in Prison
  • Shai-Hulud Supply Chain Attack: Worm Used to Steal Secrets, 180+ NPM Packages Hit

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News