การยินยอมใช้คุกกี้

COOKIE CONSENT

เราใช้คุกกี้เพื่อปรับปรุงประสบการณ์การใช้งาน วิเคราะห์การเข้าใช้เว็บไซต์ และนำเสนอเนื้อหาที่เกี่ยวข้อง ท่านสามารถเลือกประเภทคุกกี้ที่ยินยอมได้ ดูรายละเอียดเพิ่มเติมใน ประกาศคุกกี้

Ransomware

The Evolution of Modern Cybercrime: Analyzing Scattered Spider and The Com in 2025

FORTSECURE GLOBAL· 2026-08-10🛰 IT Governance Blog
#Ransomware#Social Engineering#Cyber Crime#Threat Intelligence#Identity Access Management

Recent attacks by Scattered Spider reveal a shifting landscape in cybercrime where social engineering meets sophisticated technical bypasses.

The Rise of Social Engineering 2.0\n\nAs we move through 2025, the threat landscape has been dominated by highly agile and socially adept threat actors, most notably the group known as Scattered Spider. At FORTSECURE GLOBAL, our threat intelligence team has observed a significant shift in how these groups operate. Unlike traditional ransomware gangs that rely heavily on malware payloads, Scattered Spider utilizes advanced social engineering techniques to gain initial access. They often target help desks and IT administrators, using 'vishing' (voice phishing) and SIM swapping to bypass Multi-Factor Authentication (MFA).\n\nWhat makes this group particularly dangerous is their connection to a broader subculture known as "The Com." This community consists of young, tech-savvy individuals who collaborate across various platforms to trade exploits, stolen credentials, and techniques. The 2025 attacks have shown that these adversaries are not just looking for a quick payout; they are experts at lateral movement and data exfiltration, often dwelling in a network for weeks to ensure they have maximum leverage before deploying ransomware or initiating extortion.\n\n## Defending Against Modern Adversaries\n\nTraditional perimeter defenses are no longer sufficient against attackers who can simply 'ask' for the keys to your kingdom. To defend against groups like Scattered Spider, organizations must pivot toward an identity-centric security model. This means moving beyond simple SMS or push-based MFA, which are easily phished or bypassed via MFA fatigue attacks.\n\n### Practical Recommendations:\n\n1. Adopt Phishing-Resistant MFA: Transition to FIDO2-based hardware security keys or passkeys. These technologies are virtually immune to modern social engineering and proxy-based phishing attacks.\n2. Enhance Help Desk Protocols: Implement strict identity verification processes for password resets and MFA device enrollments. Never rely on caller ID or easily spoofed personal information.\n3. Monitor for Session Hijacking: Use User and Entity Behavior Analytics (UEBA) to detect unusual login patterns, such as 'impossible travel' or session token theft, which are common indicators of a Scattered Spider intrusion.


แหล่งที่มา: IT Governance Blog เผยแพร่ครั้งแรก: Fri, 10 Jul 2026 12:43:49 +0000 บทความต้นฉบับ: อ่านต้นฉบับ

Source Attribution

แหล่งที่มา: IT Governance Blog

เผยแพร่ครั้งแรก: Fri, 10 Jul 2026 12:43:49 +0000

บทความต้นฉบับ: https://grcsolutions.io/scattered-spider-and-the-com-what-the-2025-attacks-reveal/

อ่านบทความต้นฉบับ ↗

* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์

← กลับไปหน้า Blog