what is unique about Scattered Spider and BlackCat

2023-09-18 17:02:32

Hacked Las Vegas: what makes Scattered Spider and BlackCat unique

Everyone already knows about the attacks on MGM and Caesars, but how did the criminals manage to do it?

Two of Las Vegas’ leading entertainment corporations, MGM and Caesars, collided
with large-scale hacker attacks. MGM’s systems were shut down at all 31 resorts while Caesars paid the attackers multimillion-dollar sums to avoid a similar fate.

According to sources, the attacks were carried out by the hacker group Scattered Spider (in partnership with ALPHV, also known as BlackCat). This group, which includes US and UK citizens, began its activity in May 2022.

“The social engineering methods they use are highly sophisticated. These hackers specialize in voice phishing attacks that target help desks, call centers, and even security operations centers,” said Stephen Ervin, senior consultant at TrustedSec.

Various methods of social engineering are another feature of Scattered Spider. Phishing campaigns are mainly carried out through Telegram, SMS and SIM swapping.

For initial penetration into the system it is used

Two-factor authentication (2FA) is a method of verifying a user’s identity using two different authentication steps that provide “two layers” of account protection against unauthorized access. At the first stage, as a rule, a standard login/password combination is requested. At the second stage, most often, a short code received via SMS or email. Sometimes the second step uses a USB token or a person’s biometric data.
Two-factor authentication reliably protects online accounts from most vulnerabilities.

” data-html=”true” data-original-title=”Two-Factor Authentication”>Two-Factor Authentication (MFA). The victim is sent numerous requests to confirm his identity. Hackers expect that intrusive notifications will be annoying and the user will eventually agree to enter his data.

In addition, attackers are exploiting known vulnerabilities associated with Ethernet card drivers. Intel is an American corporation that produces a wide range of electronic devices and computer components, in particular microprocessors and system logic sets. Almost 100% of the company’s shares are publicly traded on stock exchanges.

Related Articles:  New Lada Vesta - less components, higher price

Intel Corporation is one of the world’s largest microprocessor manufacturers, with a 75% market share. Among the company’s main clients are personal computer manufacturers Dell and Hewlett-Packard. In addition to microprocessors, Intel also produces semiconductor components for industrial and networking equipment.

” data-html=”true” data-original-title=”Intel”>Intel to carry out DoS (denial of service) attacks. One of these vulnerabilities is CVE-2015-2291 .

Once a system has been successfully infiltrated, hackers can quickly move through the network, using stolen credentials or tokens to attack cloud resources.

“After being highly effective in penetration methods, they quickly move on to installing ransomware or compromising data,” says Juan Perez, another researcher at TrustedSec.

The alliance between Scattered Spider and ALPHV/BlackCat allows them to expand their capabilities. There is information that Scattered Spider is a division of BlackCat, but experts have not yet been able to verify its authenticity.

The BlackCat ransomware virus was first discovered in 2021. This group develops and sells ransomware as a service (RaaS) malware. The Rust programming language is used to create it.

Some of the hackers are believed to be as young as 19 years old, but their activity and professionalism are causing serious concern among cybersecurity experts.

1695067863
#unique #Scattered #Spider #BlackCat

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.