Cybersecurity News in Asia

RECENT STORIES:

SEGA moves faster with flow-based network monitoring
The cyber incident that is too “isolated” to accentuate to mass media...
Sparsa AI Launches Sovereign Enterprise AI Platform with Global Deploy...
Conifers AI Opens Singapore Data Region, Bringing Local Data Residency...
Finally taken down: Residential proxy network of at least 2m smart dev...
DXC Opens Flagship AI-first Customer Experience Center in Bengaluru
LOGIN REGISTER
CybersecAsia
  • Features
    • Featured

      S E Asia governments targeted by cyber-espionage group

      S E Asia governments targeted by cyber-espionage group

      Tuesday, June 23, 2026, 8:00 AM Asia/Singapore | Features
    • Featured

      Rethinking network and infrastructure design for resilience

      Rethinking network and infrastructure design for resilience

      Thursday, June 18, 2026, 2:17 PM Asia/Singapore | Features
    • Featured

      Bringing cybercriminals to justice in APAC

      Bringing cybercriminals to justice in APAC

      Thursday, June 11, 2026, 10:30 AM Asia/Singapore | Features
  • Opinions
  • Tips
  • Whitepapers
  • AWARDS 2026
  • Directory
  • E-Learning

Select Page

News

Scattered Spider: still spinning phishing webs on corporate land?

By CybersecAsia editors | Wednesday, May 14, 2025, 11:03 AM Asia/Singapore

Scattered Spider: still spinning phishing webs on corporate land?

Despite law enforcement crackdowns, questions remain about the group’s resurgence, evolving phishing tactics, and ongoing risks to organizations.

Remember the saga involving the threat group Scattered Spider (UNC3944)?

The threat group gained notoriety by inflicting damage on major corporations and prominent Las Vegas casinos in 2023.

Known for their past association with BlackCat/ALPHV, Scatter Spider (SS in short) developed playbooks for highly successful, reproducible attacks, often using social engineering to gain access to identities. While many attackers use identity pathways, SS is notoriously slick at bypassing multi-factor authentication and infiltrating enterprises through cloud identities.

In a recent update, the Google Threat Intelligence Group (GTIG) had confirmed the threat group’s decline in activity after 2024 law enforcement actions against individuals allegedly associated with the group.

The GTIG warns that threat actors will often temporarily halt or significantly curtail operations after an arrest, possibly to reduce law enforcement attention, rebuild capabilities and/or partnerships, or shift to new tooling to evade detection. Also:

  • UNC3944’s existing ties to a broader community of threat actors could potentially help them recover from law enforcement actions more quickly.
  • Recent public reporting has suggested that threat actors used tactics consistent with SS to target a UK retail organization and deploy DragonForce ransomware.
  • Subsequent reporting by BBC News indicates that actors associated with DragonForce had claimed responsibility for attempted attacks at multiple UK retailers. Notably, the operators of DragonForce ransomware recently claimed control of RansomHub, a ransomware-as-a-service threat that seemingly ceased operations in March 2025. SS was an affiliate of RansomHub in 2024, after the ALPHV (aka Blackcat) shut down.

Mitigating against possible SS resurrection

GTIG has not independently confirmed the involvement of SS or DragonForce groups in its own research because, according to its chief analyst, John Hultquist: “(Threat) actors pass in and out, and the associations aren’t extremely firm. That can make it hard to do attribution, and it can make it hard to completely put a stop to their activity. Historically these actors have gone after sectors in waves… and the trend in UK retail shouldn’t be ignored. There’s an opportunity for the sector to take proactive action, especially against the preferred tactics of these actors, like social engineering.”

Just in case, to harden against SS threats, organizations can follow standard best practices: enforce phishing-resistant multi-factor authentication; strictly control password resets and MFA registration; segregate privileged accounts; monitor endpoints and cloud for anomalies; restrict lateral movement; educate staff about social engineering threats; and ensure comprehensive security observability.

Share:

PreviousTaiPei-based Hong Tong Technology Acquires Initio’s Entire Encryption Division.
NextNavigating blockchain adoption amid rising security challenges

Related Posts

Is your organization a digital trust leader, a laggard or somewhere in-between?

Is your organization a digital trust leader, a laggard or somewhere in-between?

Tuesday, March 26, 2024

Why spend more on cybersecurity? Use the funds to digitalize!

Why spend more on cybersecurity? Use the funds to digitalize!

Wednesday, November 17, 2021

Do ransomware attacks cripple the confidence of the IT teams affected?

Do ransomware attacks cripple the confidence of the IT teams affected?

Thursday, October 22, 2020

Do complicated registration- and log-in processes lead to cart abandonment?

Do complicated registration and log-in processes lead to cart abandonment?

Thursday, July 29, 2021

Leave a reply Cancel reply

You must be logged in to post a comment.

Voters-draw/RCA-Sponsors

Slide

CybersecAsia Voting Placement

Gamification listing or Participate Now

PARTICIPATE NOW

Vote Now -Placement(Google Ads)

Top-Sidebar-banner

Whitepapers

  • Critical Security Threatsand the Need for ZTNA: How evolving cyberattacks demand a Zero Trust approach

    Critical Security Threatsand the Need for ZTNA: How evolving cyberattacks demand a Zero Trust approach

    Cyber threats have become more frequent and sophisticated, targeting organizations of all sizes across all …Download Whitepaper
  • Zero Trust Made Simple: Why it matters and how to get started

    Zero Trust Made Simple: Why it matters and how to get started

    Data breaches and cyberattacks are no longer limited to large, high-profile organizations.Download Whitepaper
  • Cloud Secure Edge: Remote access, better security

    Cloud Secure Edge: Remote access, better security

    ​SonicWall Cloud Secure Edge™ is a modern, cloud-native Security Service Edge (SSE) solution that addresses …Download Whitepaper
  • Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Insider threats continue to be a major cybersecurity risk in 2024. Explore more insights on …Download Whitepaper

Middle-sidebar-banner

Case Studies

  • How a Vietnamese D2C retailer built its own secure digital infrastructure

    How a Vietnamese D2C retailer built its own secure digital infrastructure

    Would your organization build your own digital infrastructure – including AI governance and cybersecurity – …Read more
  • Cyber protection for medical clinics in Singapore

    Cyber protection for medical clinics in Singapore

    As Singapore’s healthcare sector becomes increasingly digital and interconnected, clinics are facing heightened cyber risks, …Read more
  • India’s WazirX strengthens governance and digital asset security

    India’s WazirX strengthens governance and digital asset security

    Revamping its custody infrastructure using multi‑party computation tools has improved operational resilience and institutional‑grade safeguardsRead more
  • Bangladesh LGED modernizes communication while addressing data security concerns

    Bangladesh LGED modernizes communication while addressing data security concerns

    To meet emerging data localization/privacy regulations, the government engineering agency deploys a secure, unified digital …Read more

Bottom sidebar

Other News

  • Sparsa AI Launches Sovereign Enterprise AI Platform with Global Deployment at QNET

    Wednesday, July 8, 2026
    The Sparsa AI Enterprise Operating …Read More »
  • Conifers AI Opens Singapore Data Region, Bringing Local Data Residency to Asia-Pacific Security Teams

    Wednesday, July 8, 2026
    With data regions now spanning …Read More »
  • DXC Opens Flagship AI-first Customer Experience Center in Bengaluru

    Tuesday, July 7, 2026
    Strengthens DXC’s India presence with …Read More »
  • D-Link Brings Advanced AI Fall Detection and Privacy Protection to Home Elderly Care with the New DCS-8610 Wi-Fi Camera

    Monday, July 6, 2026
    Advanced technologies traditionally found in …Read More »
  • ICAC Commissioner attends first IAACA European regional anti-corruption conference in Hungary

    Friday, July 3, 2026
    BUDAPEST, Hungary, July 2, 2026 …Read More »
  • Our Brands
  • DigiconAsia
  • MartechAsia
  • Home
  • About Us
  • Contact Us
  • Sitemap
  • Privacy & Cookies
  • Terms of Use
  • Advertising & Reprint Policy
  • Media Kit
  • Subscribe
  • Manage Subscriptions
  • Newsletter

Copyright © 2026 CybersecAsia All Rights Reserved.