1
Threat Overview
The 'Scattered Spider' cybercrime group used text-message phishing attacks to hack into major technology companies and steal tens of millions of dollars worth of cryptocurrency from investors. A senior member, Tyler Robert Buchanan, pleaded guilty to wire fraud conspiracy and aggravated identity theft. The attacks targeted at least a dozen major technology companies.
2
Key Intelligence Points
1. The attackers used text-message phishing attacks as the primary attack vector. 2. The attacks targeted at least a dozen major technology companies, resulting in tens of millions of dollars worth of cryptocurrency theft. 3. The attackers exploited the trust of investors to gain access to their accounts and steal cryptocurrency. 4. Detection opportunities include monitoring for suspicious text messages and unusual account activity.
3
MITRE ATT&CK Techniques
T1566.001 Spearphishing via SMS
4
Mitigation & Detection
Implement robust phishing detection and prevention measures, such as multi-factor authentication and regular security awareness training for employees.