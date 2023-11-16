In a joint cybersecurity advisory on Tuesday, CISA detailed dangerous techniques leveraged by Scattered Spider, the threat group reportedly behind a series of high-profile and disruptive cyber attacks.

Since emerging onto the threat landscape in 2022, Scattered Spider has been observed conducting sophisticated social engineering attacks, employing successful evasion techniques, and deploying Alphv/BlackCat ransomware to extort victim organizations. Cybersecurity companies attributed Scattered Spider to recent attacks against Okta, MGM Resorts and Caesar's Entertainment, which caused prolonged disruptions and set MGM back $100 million in losses.

The attacks warranted a joint cybersecurity advisory co-authored by the FBI and CISA. By documenting tactics, techniques, and procedures (TTPs) obtained through FBI investigations, the advisory aims to alert enterprises to the most current Scattered Spider activity and provide mitigations. It was published one day after Reuters reported that security vendors and incident responders were frustrated with the FBI for its inability to make any arrests related to the Las Vegas casino attacks.

CISA said the advisory was published "in response to recent activity by Scattered Spider threat actors against the commercial facilities sectors and subsectors." The sector includes gaming, lodging and entertainment companies.