TechCrunch News 2024年11月23日
The rise and fall of the ‘Scattered Spider’ hackers
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

Scattered Spider是一个活跃两年多的黑客组织,其成员主要为青少年,他们利用社交工程、网络钓鱼等手段攻击了全球众多科技公司,包括Okta、Caesars Entertainment、Coinbase等,造成严重损失。该组织与其他黑客组织存在交叉,且部分成员涉嫌线下犯罪行为。经过两年多的追捕,美国司法部逮捕了五名Scattered Spider成员,英国警方也逮捕了一名涉案青少年。此事件警示企业加强网络安全防护,并关注青少年网络犯罪问题。

🤔Scattered Spider是一个活跃两年多的黑客组织,其成员主要为青少年,他们通过社交工程、网络钓鱼、SIM卡换卡等手段,攻击了全球130多家公司,包括Okta、Caesars Entertainment、Coinbase等,窃取了近1万名员工的凭证。

💻Scattered Spider与其他黑客组织存在交叉,例如0ktapus和the Com,且部分成员涉嫌参与线下犯罪活动,包括抢劫、入室盗窃、以及恶意报警等,给受害者造成严重后果。

🚨美国司法部逮捕了五名Scattered Spider成员,包括Ahmed Hossam Eldin Elbadawy、Noah Michael Urban、Evans Onyeaka Osiebo、Joel Martin Evans和Tyler Robert Buchanan,英国警方也逮捕了一名17岁的涉案青少年,标志着对该组织的打击取得了初步成果。

⚠️该组织利用青少年身份逃避法律制裁,也警示了企业需要加强网络安全防护,防范此类黑客攻击,同时关注青少年网络犯罪问题,并加强对未成年人的网络安全教育。

🔍CISA和FBI发布了关于Scattered Spider的警示,提醒企业注意该组织的攻击手段和目标,并采取相应的防御措施。

After evading capture for more than two years following a hacking spree that targeted some of the world’s biggest tech companies, U.S. authorities say they have finally caught at least some of the hackers responsible.

In August 2022, security researchers went public with a warning that a group of hackers had targeted over 130 organizations as part of a sophisticated phishing campaign that stole the credentials of almost 10,000 employees. The hackers were specifically targeting companies that used Okta, a single sign-on provider used by thousands of companies worldwide to let their employees log in from home. 

Because of its focus on Okta, the hacking group was dubbed “0ktapus.” To date, the group hacked Caesars Entertainment, Coinbase, DoorDash, Mailchimp, Riot Games, Twilio (twice), and dozens more

The hackers’ most notable sizable cyberattack by way of downtime and impact was the hack against MGM Resorts in September 2023, which reportedly cost the casino and hotel giant at least $100 million. In that case, the hackers worked with the Russian-speaking ransomware gang ALPHV, and demanded a ransom from MGM for the company to get its files back. The hack was so disruptive that the casinos owned by MGM had trouble providing services for days.

For the last two years, as law enforcement has been closing in on the hackers, people in the cybersecurity industry tried to figure out exactly how to categorize the hackers and whether to put them in one group or another. 

The hackers’ techniques, such as social engineering, email and text message phishing, and SIM swapping, are common and widespread. Some of the individual hackers were part of several groups responsible for different data breaches. These circumstances have made it difficult to understand exactly who belongs in what group. Cybersecurity giant CrowdStrike dubbed this umbrella group of hackers “Scattered Spider,” and researchers believe there is some overlap with 0ktapus.

The group was so active — and successful — that U.S. cybersecurity agency CISA and the FBI issued an advisory in late 2023 with details on the group’s activities and techniques, in an attempt to help organizations prepare for and defend against anticipated attacks. 

Scattered Spider is “a cybercriminal group that targets large companies and their contracted IT help desks,” CISA wrote in its advisory. The agency warned that the group “have typically engaged in data theft for extortion,” and noted their known links to ransomware gangs.

One thing that’s relatively certain is that the hackers are mostly English-speaking, and widely believed to be in their teens and early-20s — and sometimes referred to as “advanced persistent teenagers.”

“There is a disproportionate number of minors involved, and that’s because the group deliberately recruits minors because of the lenient legal environment these minors exist in and they know nothing will happen to them if the police catch a kid,” Allison Nixon, chief research officer at Unit 221B, told TechCrunch at the time.

Over the last two years, some of the members of 0ktapus and Scattered Spider have been linked with a similarly nebulous group of cybercriminals known as “the Com.” People in this wider cybercrime community have committed crimes that crossed over into the real world. Some of them have been responsible for violent acts, such as robberies, burglaries, and brickings — hiring thugs to throw bricks at someone’s house or apartment; as well as swatting — where someone tricks authorities into believing there’s a violent crime happening, triggering the armed police unit to intervene. While born as a prank, swatting is known to have fatal consequences

After two years of hacking, authorities are finally starting to identify and charge members of Scattered Spider. 

In July, U.K. police confirmed the arrest of a 17-year-old in connection to the hack at MGM.

In November, the U.S. Department of Justice announced that it had indicted five hackers: Ahmed Hossam Eldin Elbadawy, 23, of College Station, Texas; Noah Michael Urban, 20, of Palm Coast, Florida, who had been arrested in January; Evans Onyeaka Osiebo, 20, of Dallas, Texas; Joel Martin Evans, 25, of Jacksonville, North Carolina; and Tyler Robert Buchanan, 22, from the United Kingdom, who was arrested in June in Spain.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

Scattered Spider 黑客 网络安全 网络犯罪 青少年犯罪
相关文章