THREAT FIELD NOTESINTELLIGENCE FOR DEFENDERS
Back to home

Threat actors and campaigns

Compact profiles that connect names, behaviors, targets, and the defensive questions that matter.

Cluster · ActiveAlso tracked as UNC3944

Scattered Spider

A financially motivated cluster known for identity attacks, helpdesk manipulation, SIM swapping, and cloud-focused intrusion.

Social engineeringIdentityCloud
Brief overview

Scattered Spider often begins with research on employees and high-pressure social engineering against users or helpdesks. After obtaining credentials, operators have created accounts, changed MFA methods, used legitimate remote-management tooling, and explored cloud environments. The name covers a changing cluster, so defenders should prioritize repeatable behavior over a fixed list of infrastructure.

Behavioral indicators

  • Unexpected password resets or MFA enrollment following a helpdesk interaction
  • New cloud identities, privilege changes, or remote-access tools without an approved change
  • Phishing domains imitating corporate identity, SSO, or support portals

Defender next steps

  • Require phishing-resistant MFA for privileged and remote access.
  • Use out-of-band identity verification for password resets and MFA recovery.
  • Alert on new accounts, MFA changes, SaaS administrator actions, and first-seen remote tools.

MITRE ATT&CK mapping

T1589 · Gather Victim Identity InformationT1598 · Phishing for InformationT1078 · Valid AccountsT1136 · Create Account
Read the joint advisory
Ransomware · ActiveCampaign profile

LockBit ecosystem

A ransomware-as-a-service operation whose affiliate model produces varied intrusion paths but recognizable impact-stage behaviors.

RansomwareExtortionAffiliates
Brief overview

LockBit operators provide ransomware and supporting infrastructure while affiliates conduct intrusions, so tools and initial-access methods differ between incidents. Common patterns include credential theft, remote services, lateral movement through SMB or PsExec, data staging and exfiltration, attempts to impair defenses, and encryption across Windows or virtualized environments.

Behavioral indicators

  • Unexpected PsExec, SMB administration, RDP, AnyDesk, ScreenConnect, or similar remote tooling
  • Attempts to stop endpoint protection, clear Windows event logs, or delete shadow copies
  • Large archives or unusual Rclone, MEGA, FileZilla, or cloud-storage transfers

Defender next steps

  • Enforce MFA on VPN, email, and privileged accounts and close unused remote services.
  • Segment administrative paths and restrict SMB and RDP between user and server networks.
  • Maintain offline, tested backups and alert when security tools or recovery services are disabled.

MITRE ATT&CK mapping

T1569.002 · Service ExecutionT1562.001 · Impair DefensesT1070.001 · Clear Windows Event LogsT1486 · Data Encrypted for Impact
Read the LockBit advisory
Espionage · ActiveActor profile

Volt Typhoon

A PRC state-sponsored cluster associated with long-term access and living-off-the-land activity in critical infrastructure.

LOTLCritical infrastructureEspionage
Brief overview

Volt Typhoon has relied heavily on stolen valid accounts, built-in administration tools, command shells, WMI, and compromised network infrastructure. This tradecraft can resemble legitimate administration and may leave fewer malware artifacts, making identity, network-device, and command-line telemetry especially important during hunting.

Behavioral indicators

  • Unusual command-shell, PowerShell, WMIC, or proxy activity from administrative or network devices
  • Valid accounts used from unfamiliar infrastructure, at unusual times, or across segmented systems
  • Configuration changes or new administrative access on edge appliances without a matching ticket

Defender next steps

  • Centralize logs from identity systems, endpoints, firewalls, routers, and VPN appliances.
  • Rotate credentials that have touched compromised edge devices and review least privilege.
  • Baseline legitimate administrative commands so living-off-the-land anomalies are visible.

MITRE ATT&CK mapping

T1059 · Command and Scripting InterpreterT1047 · Windows Management InstrumentationT1078 · Valid AccountsT1068 · Exploitation for Privilege Escalation
Read the Volt Typhoon advisory
Malware · ActiveMalware profile

Lumma Stealer

A Windows information stealer sold as a service and used to collect browser data, credentials, tokens, and cryptocurrency information.

InfostealerCredentialsMalvertising
Brief overview

Lumma Stealer is commonly delivered through deceptive downloads, malicious archives, fake software, or fake CAPTCHA instructions that persuade a user to run a command. Observed behavior includes browser-information discovery, automated collection, Run-key persistence, sandbox checks, encrypted web communications, and exfiltration over its command-and-control channel.

Behavioral indicators

  • Users prompted by a website to paste a command into Windows Run or PowerShell
  • Unexpected Run-key persistence, hidden script windows, or DLL side-loading
  • Browser credential access followed by HTTPS connections from an unusual process

Defender next steps

  • Block untrusted scripts and downloads and train users never to paste commands from web prompts.
  • Isolate suspected hosts, preserve evidence, and reimage when credential theft is confirmed.
  • Rotate passwords, session tokens, API keys, and wallet secrets from a clean device.

MITRE ATT&CK mapping

T1204 · User ExecutionT1547.001 · Registry Run Keys / Startup FolderT1217 · Browser Information DiscoveryT1041 · Exfiltration Over C2 Channel
View the MITRE software profile