{"id":1235,"date":"2024-10-20T18:39:43","date_gmt":"2024-10-20T13:09:43","guid":{"rendered":"https:\/\/nocturnalknight.co\/?p=1235"},"modified":"2024-10-20T18:39:43","modified_gmt":"2024-10-20T13:09:43","slug":"scattered-spider-attacks-tips-for-saas-security","status":"publish","type":"post","link":"http:\/\/3.10.118.248\/?p=1235","title":{"rendered":"Scattered Spider Attacks: Tips for SaaS Security"},"content":{"rendered":"\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"585\" src=\"http:\/\/3.10.118.248\/wp-content\/uploads\/2024\/10\/A_dynamic_16_9_hero_image_resized-min-1024x585.png\" alt=\"\" class=\"wp-image-1243\" srcset=\"http:\/\/3.10.118.248\/wp-content\/uploads\/2024\/10\/A_dynamic_16_9_hero_image_resized-min-1024x585.png 1024w, http:\/\/3.10.118.248\/wp-content\/uploads\/2024\/10\/A_dynamic_16_9_hero_image_resized-min-300x171.png 300w, http:\/\/3.10.118.248\/wp-content\/uploads\/2024\/10\/A_dynamic_16_9_hero_image_resized-min-768x439.png 768w, http:\/\/3.10.118.248\/wp-content\/uploads\/2024\/10\/A_dynamic_16_9_hero_image_resized-min-1536x878.png 1536w, http:\/\/3.10.118.248\/wp-content\/uploads\/2024\/10\/A_dynamic_16_9_hero_image_resized-min.png 1792w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">As cloud adoption soars, threat groups like <a href=\"https:\/\/en.wikipedia.org\/wiki\/Scattered_Spider\" target=\"_blank\" rel=\"noopener\" title=\"\">LUCR-3<\/a> Scattered Spider and Oktapus are mastering new ways to exploit identity management systems(IAMs), making these attacks more frequent and harder to detect. By targeting cloud environments and leveraging human vulnerabilities, LUCR-3 compromises identity providers (IDPs) and uses sophisticated techniques to breach organizations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Before we begin, I wanted to present a random sampling of the successful attacks carried over by the LUCR-3 aka Scattered Spider.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th><strong>Company\/Product<\/strong><\/th><th><strong>Date Attacked<\/strong><\/th><th><strong>Compromised System<\/strong><\/th><th><strong>Projected Loss<\/strong><\/th><th><strong>Mitigation Time<\/strong><\/th><\/tr><\/thead><tbody><tr><td><strong>Telecom Company (Unnamed)<\/strong><\/td><td>December 2022<\/td><td>Mobile Carrier Network, IDP Systems<\/td><td>Estimated millions in damages<\/td><td>Several weeks (ongoing)\u200b<a href=\"https:\/\/www.crowdstrike.com\/en-us\/blog\/scattered-spider-attempts-to-avoid-detection-with-bring-your-own-vulnerable-driver-tactic\/\" target=\"_blank\" rel=\"noreferrer noopener\">CrowdStrike<\/a><\/td><\/tr><tr><td><strong>Octa (Roasted Oktapus)<\/strong><\/td><td>March 2022<\/td><td>Identity Provider (Okta) and SaaS<\/td><td>Potential damage to ~366 companies<\/td><td>4-5 weeks\u200b<a href=\"https:\/\/hero.permiso.io\/lucr-3-scattered-spider-threat-briefing\" target=\"_blank\" rel=\"noreferrer noopener\">Hero<\/a>\u200b<a href=\"https:\/\/en.wikipedia.org\/wiki\/Scattered_Spider\" target=\"_blank\" rel=\"noreferrer noopener\">Wikipedia<\/a><\/td><\/tr><tr><td><strong>British Telecommunications<\/strong><\/td><td>June 2022<\/td><td>Mobile Carrier Systems, BPO Networks<\/td><td>Millions in lost revenue<\/td><td>3-4 weeks\u200b<a href=\"https:\/\/www.crowdstrike.com\/en-us\/blog\/scattered-spider-attempts-to-avoid-detection-with-bring-your-own-vulnerable-driver-tactic\/\" target=\"_blank\" rel=\"noreferrer noopener\">CrowdStrike<\/a>\u200b<a href=\"https:\/\/hero.permiso.io\/lucr-3-scattered-spider-threat-briefing\" target=\"_blank\" rel=\"noreferrer noopener\">Hero<\/a><\/td><\/tr><tr><td><strong>Gaming Company (Unnamed)<\/strong><\/td><td>September 2022<\/td><td>Cloud Infrastructure (SaaS and IaaS)<\/td><td>Losses in IP theft (unconfirmed)<\/td><td>~2 weeks\u200b<a href=\"https:\/\/permiso.io\/blog\/lucr-3-scattered-spider-getting-saas-y-in-the-cloud\" target=\"_blank\" rel=\"noreferrer noopener\">ISPM ITDR<\/a><\/td><\/tr><tr><td><strong>Cloud Hosting Provider<\/strong><\/td><td>November 2022<\/td><td>AWS, Azure Environments, IAM Systems<\/td><td>IP theft and reputational damage<\/td><td>3 weeks\u200b<a href=\"https:\/\/www.crowdstrike.com\/en-us\/blog\/scattered-spider-attempts-to-avoid-detection-with-bring-your-own-vulnerable-driver-tactic\/\" target=\"_blank\" rel=\"noreferrer noopener\">CrowdStrike<\/a><\/td><\/tr><tr><td><strong>MGM Resorts<\/strong><\/td><td>September 2023<\/td><td>Corporate systems, Help Desk, and IDP<\/td><td>Millions in lost revenue<\/td><td>Systems offline for weeks\u200b<a href=\"https:\/\/en.wikipedia.org\/wiki\/Scattered_Spider\" target=\"_blank\" rel=\"noreferrer noopener\">Wikipedia<\/a><\/td><\/tr><tr><td><strong>Caesars Entertainment<\/strong><\/td><td>September 2023<\/td><td>Identity Providers (IDP) and SaaS<\/td><td>~$30 million ransom paid\u200b <a href=\"https:\/\/en.wikipedia.org\/wiki\/Scattered_Spider\" target=\"_blank\" rel=\"noreferrer noopener\">Wikipedia<\/a><\/td><td>~1 month recovery\u200b<a href=\"https:\/\/www.cyberdefensemagazine.com\/how-the-security-of-the-clouds-supply-chain-will-shift-in-2024\/\" target=\"_blank\" rel=\"noreferrer noopener\">Cyber Defense Magazine<\/a><\/td><\/tr><tr><td><strong>Charter Communications<\/strong><\/td><td>April 2024<\/td><td>Cloud-based systems (Okta phishing)<\/td><td>Potentially millions in damages\u200b<a href=\"https:\/\/www.cyberresilience.com\/threatonomics\/resilience-threat-researchers-identify-new-campaigns-from-scattered-spider\/\" target=\"_blank\" rel=\"noreferrer noopener\"> Resilience<\/a><\/td><td>Several weeks<\/td><\/tr><tr><td><strong>NHS Hospitals (UK)<\/strong><\/td><td>June 2024<\/td><td>VMware ESXi servers, critical healthcare systems<\/td><td>Disruption of hundreds of operations\u200b<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/microsoft-links-scattered-spider-hackers-to-qilin-ransomware-attacks\/\" target=\"_blank\" rel=\"noreferrer noopener\">BleepingComputer<\/a><\/td><td>Ongoing\u200b<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/microsoft-links-scattered-spider-hackers-to-qilin-ransomware-attacks\/\" target=\"_blank\" rel=\"noreferrer noopener\">BleepingComputer<\/a><\/td><\/tr><tr><td><strong>Synnovis Pathology Services<\/strong><\/td><td>June 2024<\/td><td>Ransomware on pathology services systems<\/td><td>Estimated millions in healthcare disruptions\u200b<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/microsoft-links-scattered-spider-hackers-to-qilin-ransomware-attacks\/\" target=\"_blank\" rel=\"noreferrer noopener\">BleepingComputer<\/a><\/td><td>Ongoing investigation\u200b<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/microsoft-links-scattered-spider-hackers-to-qilin-ransomware-attacks\/\" target=\"_blank\" rel=\"noreferrer noopener\">BleepingComputer<\/a><\/td><\/tr><\/tbody><\/table><figcaption class=\"wp-element-caption\">This table provides a detailed overview of Scattered Spider\u2019s recent attacks across industries, demonstrating their evolving tactics and widespread impact.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">This article outlines the technical steps LUCR-3 typically follows, from initial access to persistence and lateral movement within cloud environments, mostly targeting SaaS platforms.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Step 1: Initial Access Through Identity Compromise<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">LUCR-3 starts with a core weakness in modern security\u2014<strong>identity management<\/strong>. Their main attack vectors include:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>SIM Swapping<\/strong>: LUCR-3 hijacks a user\u2019s phone number by tricking the telecom provider into assigning the number to a new SIM card. Once they have control over the phone number, they can intercept <strong>One-Time Passwords (OTP)<\/strong> sent via SMS.<\/li>\n\n\n\n<li><strong>MFA Fatigue<\/strong>: The attackers flood the target with repeated MFA prompts, often overwhelming them into approving a malicious login request.<\/li>\n\n\n\n<li><strong>Phishing and Social Engineering<\/strong>: They set up fake login pages for SaaS applications (e.g., SharePoint or OneDrive), capturing legitimate credentials and OTP codes.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">These techniques allow LUCR-3 to bypass standard <strong>Multi-Factor Authentication (MFA)<\/strong> protections and gain access to cloud environments\u200b<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/permiso.io\/blog\/lucr-3-scattered-spider-getting-saas-y-in-the-cloud\" target=\"_blank\" rel=\"noreferrer noopener\">ISPM ITDR<\/a>, <a href=\"https:\/\/hero.permiso.io\/lucr-3-scattered-spider-threat-briefing\" target=\"_blank\" rel=\"noreferrer noopener\">Hero<\/a>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Step 2: Bypassing MFA and Establishing a Foothold<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Once inside, LUCR-3 focuses on maintaining access to the compromised identity. This is done by modifying the victim&#8217;s MFA settings. Their tactics include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Registering New Devices<\/strong>: LUCR-3 will register their own devices (phones or emails) under the victim\u2019s account, which ensures they can log in without triggering alerts. For example, they might register an iPhone if the victim previously used Android, raising minimal suspicion.<\/li>\n\n\n\n<li><strong>Adding Alternate MFA Methods<\/strong>: They add backup MFA methods, such as an external email address, making it even harder to lock them out if the breach is discovered\u200b<a href=\"https:\/\/permiso.io\/blog\/lucr-3-scattered-spider-getting-saas-y-in-the-cloud\" target=\"_blank\" rel=\"noreferrer noopener\">ISPM ITDR<\/a>.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Step 3: Reconnaissance and Data Collection in SaaS Environments<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">After gaining access to cloud platforms, LUCR-3 conducts extensive reconnaissance to identify critical assets, credentials, and sensitive information. Here\u2019s how they do it:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>SaaS Platforms<\/strong>: They use native tools within platforms like <strong>SharePoint<\/strong>, <strong>OneDrive<\/strong>, and <strong>Salesforce<\/strong> to search for documents containing passwords, intellectual property, or financial data. They operate like legitimate users to avoid detection.<\/li>\n\n\n\n<li><strong>AWS Cloud<\/strong>: In AWS environments, LUCR-3 navigates the <strong>AWS Management Console<\/strong>, targeting services like EC2 (Elastic Compute Cloud) and S3 (Simple Storage Service). They leverage the <strong>AWS-GatherSoftwareInventory<\/strong> job through <strong>Systems Manager (SSM)<\/strong> to list running software across EC2 instances\u200b <a href=\"https:\/\/permiso.io\/blog\/lucr-3-scattered-spider-getting-saas-y-in-the-cloud\" target=\"_blank\" rel=\"noreferrer noopener\">ISPM ITDR<\/a>.<\/li>\n\n\n\n<li><strong>Privilege Escalation<\/strong>: LUCR-3 may modify <strong>IAM roles<\/strong> or escalate privileges by updating <strong>LoginProfiles<\/strong> or creating new access keys, ensuring they have continued administrative access\u200b<a href=\"https:\/\/hero.permiso.io\/lucr-3-scattered-spider-threat-briefing\" target=\"_blank\" rel=\"noreferrer noopener\">Hero<\/a>.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Step 4: Lateral Movement and Persistence<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">LUCR-3 ensures they have multiple ways to re-enter a compromised environment, even if one of their entry points is discovered. Here\u2019s how they achieve persistence:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Create New IAM Users<\/strong>: LUCR-3 creates new user accounts that align with the naming conventions of the compromised environment to avoid suspicion. These accounts often have high-level access, allowing them to continue accessing the environment even after the initial breach is patched.<\/li>\n\n\n\n<li><strong>Secrets Harvesting<\/strong>: Using tools like <strong>S3 Browser<\/strong>, LUCR-3 harvests credentials stored in <strong>AWS Secrets Manager<\/strong> and similar services, allowing them to steal sensitive data and further penetrate systems\u200b <a href=\"https:\/\/hero.permiso.io\/lucr-3-scattered-spider-threat-briefing\" target=\"_blank\" rel=\"noreferrer noopener\">Hero<\/a>.<\/li>\n\n\n\n<li><strong>MFA Manipulation<\/strong>: They alter MFA settings to ensure continued access, often registering additional email addresses or devices that align with the compromised identity.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Step 5: Data Exfiltration and Extortion<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Once LUCR-3 has gained the necessary access and gathered sensitive data, they execute their final stage of the attack, which often involves extortion. The data collected during their reconnaissance, such as customer information or proprietary code, is used as leverage to demand payment from the compromised organization\u200b  <a href=\"https:\/\/thehacker.news\/identity-based-attacks?source=below\" target=\"_blank\" rel=\"noreferrer noopener\">The Hacker News<\/a>\u200b <a href=\"https:\/\/permiso.io\/blog\/lucr-3-scattered-spider-getting-saas-y-in-the-cloud\" target=\"_blank\" rel=\"noreferrer noopener\">ISPM ITDR<\/a>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>How to Detect and Prevent LUCR-3 Attacks<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Given LUCR-3\u2019s sophisticated techniques, organizations must adopt advanced security measures to detect and mitigate such attacks:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Monitor MFA Changes<\/strong>: Keep a close watch for unusual changes in MFA settings, such as new device registrations or changes from app-based authentication to SMS-based methods.<\/li>\n\n\n\n<li><strong>Audit Cloud Logs<\/strong>: Regularly audit cloud environments, especially IAM policy changes, new access key creation, and suspicious activity in management consoles.<\/li>\n\n\n\n<li><strong>Behavioral Anomaly Detection<\/strong>: Implement advanced behavioral monitoring to detect when legitimate accounts are being used in unusual ways, such as accessing unfamiliar services or using unfamiliar devices.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Conclusion<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">LUCR-3 (Scattered Spider) represents a new breed of cyber threat actors that rely on identity compromise rather than malware or brute force. By targeting the very foundation of security\u2014identity\u2014they can infiltrate cloud environments, move laterally, and exfiltrate data with relative ease. As organizations increasingly rely on cloud services, strengthening identity management, closely monitoring for anomalies, and responding quickly to suspicious behavior are critical defenses against such attacks.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>References and Further Reading<\/strong><\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>The Hacker News<\/strong>: Provides a detailed breakdown of LUCR-3\u2019s identity-based attacks across cloud environments, lateral movement techniques, and persistence strategies.\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/thehacker.news\/identity-based-attacks?source=below\">Read more<\/a>\u200b<a href=\"https:\/\/thehacker.news\/identity-based-attacks?source=below\" target=\"_blank\" rel=\"noreferrer noopener\">The Hacker News<\/a>.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Permiso.io<\/strong>: Discusses how LUCR-3 targets identity infrastructure, modifies MFA settings, and maintains persistence in cloud environments like AWS and Azure.\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/permiso.io\/blog\/lucr-3-scattered-spider-getting-saas-y-in-the-cloud\">Read more<\/a>\u200b<a href=\"https:\/\/permiso.io\/blog\/lucr-3-scattered-spider-getting-saas-y-in-the-cloud\" target=\"_blank\" rel=\"noreferrer noopener\">ISPM ITDR<\/a>\u200b<a href=\"https:\/\/hero.permiso.io\/lucr-3-scattered-spider-threat-briefing\" target=\"_blank\" rel=\"noreferrer noopener\">Hero<\/a>.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>CrowdStrike<\/strong>: Offers insights into Scattered Spider&#8217;s use of the Bring-Your-Own-Vulnerable-Driver (BYOVD) technique and their focus on telecom and BPO sectors.\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.crowdstrike.com\">Read more<\/a>\u200b<a href=\"https:\/\/www.crowdstrike.com\/en-us\/blog\/scattered-spider-attempts-to-avoid-detection-with-bring-your-own-vulnerable-driver-tactic\/\" target=\"_blank\" rel=\"noreferrer noopener\">CrowdStrike<\/a>.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Resilience Cyber Research<\/strong>: Highlights recent phishing campaigns by LUCR-3 in 2024, targeting industries such as telecom, food services, and tech, using Okta-based phishing tactics.\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.cyberresilience.com\">Read more<\/a>\u200b<a href=\"https:\/\/www.cyberresilience.com\/threatonomics\/resilience-threat-researchers-identify-new-campaigns-from-scattered-spider\/\" target=\"_blank\" rel=\"noreferrer noopener\">Resilience<\/a>.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>EclecticIQ<\/strong>: Discusses LUCR-3\u2019s involvement in ransomware attacks targeting cloud infrastructures within the insurance and financial sectors, leveraging smishing and phishing techniques.\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/blog.eclecticiq.com\">Read more<\/a>\u200b<a href=\"https:\/\/blog.eclecticiq.com\/ransomware-in-the-cloud-scattered-spider-targeting-insurance-and-financial-industries\" target=\"_blank\" rel=\"noreferrer noopener\">EclecticIQ Blog<\/a>.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Wikipedia (Scattered Spider)<\/strong>: Overview of the MGM Resorts hack in 2023, detailing how Scattered Spider gained access to internal systems through social engineering and caused significant disruptions.\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/en.wikipedia.org\/wiki\/Scattered_Spider\">Read more<\/a>\u200b<a href=\"https:\/\/en.wikipedia.org\/wiki\/Scattered_Spider\" target=\"_blank\" rel=\"noreferrer noopener\">Wikipedia<\/a>.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Cyber Defense Magazine<\/strong>: Discusses how LUCR-3 has highlighted vulnerabilities in MFA and cloud security, predicting more targeted attacks on SaaS and cloud service providers.\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.cyberdefensemagazine.com\">Read more<\/a>\u200b<a href=\"https:\/\/www.cyberdefensemagazine.com\/how-the-security-of-the-clouds-supply-chain-will-shift-in-2024\/\" target=\"_blank\" rel=\"noreferrer noopener\">Cyber Defense Magazine<\/a>.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>BleepingComputer<\/strong>: Provides an overview of LUCR-3\u2019s collaboration with ransomware groups like Qilin, targeting high-profile companies such as MGM Resorts and healthcare services.\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.bleepingcomputer.com\">Read more<\/a>\u200b<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/microsoft-links-scattered-spider-hackers-to-qilin-ransomware-attacks\/\" target=\"_blank\" rel=\"noreferrer noopener\">BleepingComputer<\/a>.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Caesars and MGM Hacking Incident<\/strong>: Outlines how Caesars Entertainment suffered a breach in September 2023, paying a ~$30 million ransom, while MGM Resorts experienced extensive downtime following a similar attack.\n<ul class=\"wp-block-list\">\n<li><a>Read more<\/a>\u200b<a href=\"https:\/\/en.wikipedia.org\/wiki\/Scattered_Spider\" target=\"_blank\" rel=\"noreferrer noopener\">Wikipedia<\/a>\u200b<a href=\"https:\/\/www.cyberdefensemagazine.com\/how-the-security-of-the-clouds-supply-chain-will-shift-in-2024\/\" target=\"_blank\" rel=\"noreferrer noopener\">Cyber Defense Magazine<\/a>.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Microsoft and Qilin Ransomware<\/strong>: Microsoft linked Scattered Spider to ransomware attacks using the Qilin variant, affecting companies like Synnovis Pathology and NHS hospitals in 2024. <a>Read more<\/a>\u200b <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/microsoft-links-scattered-spider-hackers-to-qilin-ransomware-attacks\/\" target=\"_blank\" rel=\"noreferrer noopener\">BleepingComputer<\/a>\u200b <a href=\"https:\/\/en.wikipedia.org\/wiki\/Scattered_Spider\" target=\"_blank\" rel=\"noreferrer noopener\">Wikipedia<\/a><\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">These resources offer in-depth insights into the attack strategies and defence mechanisms relevant to LUCR-3 (Scattered Spider), perfect for anyone looking to deepen their understanding of identity-based attacks and cloud security.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As cloud adoption soars, threat groups like LUCR-3 Scattered Spider and Oktapus are mastering new ways to exploit identity management systems(IAMs), making these attacks more frequent and harder to detect. By targeting cloud environments and leveraging human vulnerabilities, LUCR-3 compromises identity providers (IDPs) and uses sophisticated techniques to breach organizations. Before we begin, I wanted &hellip; <\/p>\n<p class=\"read-more\"><a class=\"btn btn-default\" href=\"http:\/\/3.10.118.248\/?p=1235\"> Read More<span class=\"screen-reader-text\">  Read More<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[185,75,81,142],"tags":[252,353,358,455,464],"class_list":["post-1235","post","type-post","status-publish","format-standard","hentry","category-cloud-security","category-iam","category-information-security","category-saas","tag-cloud-security","tag-iam","tag-information-security","tag-saas","tag-scattered-spider"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"As cloud adoption soars, threat groups like LUCR-3 Scattered Spider and Oktapus are mastering new ways to exploit identity management systems(IAMs), making these attacks more frequent and harder to detect. By targeting cloud environments and leveraging human vulnerabilities, LUCR-3 compromises identity providers (IDPs) and uses sophisticated techniques to breach organizations. Before we begin, I wanted\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Ramkumar Sundarakalatharan\"\/>\n\t<link rel=\"canonical\" href=\"http:\/\/3.10.118.248\/?p=1235\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_GB\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Nocturnalknight&#039;s Lair - Observations of a Random Wanderer!\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Scattered Spider Attacks: Tips for SaaS Security - Nocturnalknight&#039;s Lair\" \/>\n\t\t<meta property=\"og:description\" content=\"As cloud adoption soars, threat groups like LUCR-3 Scattered Spider and Oktapus are mastering new ways to exploit identity management systems(IAMs), making these attacks more frequent and harder to detect. By targeting cloud environments and leveraging human vulnerabilities, LUCR-3 compromises identity providers (IDPs) and uses sophisticated techniques to breach organizations. Before we begin, I wanted\" \/>\n\t\t<meta property=\"og:url\" content=\"http:\/\/3.10.118.248\/?p=1235\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2024-10-20T13:09:43+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2024-10-20T13:09:43+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@nocturnalknight\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Scattered Spider Attacks: Tips for SaaS Security - Nocturnalknight&#039;s Lair\" \/>\n\t\t<meta name=\"twitter:description\" content=\"As cloud adoption soars, threat groups like LUCR-3 Scattered Spider and Oktapus are mastering new ways to exploit identity management systems(IAMs), making these attacks more frequent and harder to detect. By targeting cloud environments and leveraging human vulnerabilities, LUCR-3 compromises identity providers (IDPs) and uses sophisticated techniques to breach organizations. Before we begin, I wanted\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@nocturnalknight\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?p=1235#blogposting\",\"name\":\"Scattered Spider Attacks: Tips for SaaS Security - Nocturnalknight's Lair\",\"headline\":\"Scattered Spider Attacks: Tips for SaaS Security\",\"author\":{\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?author=2#author\"},\"publisher\":{\"@id\":\"http:\\\/\\\/3.10.118.248\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"http:\\\/\\\/3.10.118.248\\\/wp-content\\\/uploads\\\/2024\\\/10\\\/A_dynamic_16_9_hero_image_resized-min.png\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?p=1235\\\/#articleImage\",\"width\":1792,\"height\":1024},\"datePublished\":\"2024-10-20T18:39:43+01:00\",\"dateModified\":\"2024-10-20T18:39:43+01:00\",\"inLanguage\":\"en-GB\",\"mainEntityOfPage\":{\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?p=1235#webpage\"},\"isPartOf\":{\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?p=1235#webpage\"},\"articleSection\":\"Cloud Security, IAM, Information Security, SaaS, Cloud Security, IAM, information security, saas, Scattered Spider\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?p=1235#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"http:\\\/\\\/3.10.118.248#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"http:\\\/\\\/3.10.118.248\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?cat=81#listItem\",\"name\":\"Information Security\"}},{\"@type\":\"ListItem\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?cat=81#listItem\",\"position\":2,\"name\":\"Information Security\",\"item\":\"http:\\\/\\\/3.10.118.248\\\/?cat=81\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?cat=185#listItem\",\"name\":\"Cloud Security\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"http:\\\/\\\/3.10.118.248#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?cat=185#listItem\",\"position\":3,\"name\":\"Cloud Security\",\"item\":\"http:\\\/\\\/3.10.118.248\\\/?cat=185\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?p=1235#listItem\",\"name\":\"Scattered Spider Attacks: Tips for SaaS Security\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?cat=81#listItem\",\"name\":\"Information Security\"}},{\"@type\":\"ListItem\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?p=1235#listItem\",\"position\":4,\"name\":\"Scattered Spider Attacks: Tips for SaaS Security\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?cat=185#listItem\",\"name\":\"Cloud Security\"}}]},{\"@type\":\"Organization\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/#organization\",\"name\":\"Nocturnalknight's Lair\",\"description\":\"Observations of a Random Wanderer!\",\"url\":\"http:\\\/\\\/3.10.118.248\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"http:\\\/\\\/3.10.118.248\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/cropped-Ram-Profile.avif\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?p=1235\\\/#organizationLogo\"},\"image\":{\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?p=1235\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/nocturnalknight\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/nocturnalknight\\\/\"]},{\"@type\":\"Person\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?author=2#author\",\"url\":\"http:\\\/\\\/3.10.118.248\\\/?author=2\",\"name\":\"Ramkumar Sundarakalatharan\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?p=1235#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/818bc4a4d5681de6957f83aca2601d598459bf37a0a8b17d5abb1a889e2b9298?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Ramkumar Sundarakalatharan\"}},{\"@type\":\"WebPage\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?p=1235#webpage\",\"url\":\"http:\\\/\\\/3.10.118.248\\\/?p=1235\",\"name\":\"Scattered Spider Attacks: Tips for SaaS Security - Nocturnalknight's Lair\",\"description\":\"As cloud adoption soars, threat groups like LUCR-3 Scattered Spider and Oktapus are mastering new ways to exploit identity management systems(IAMs), making these attacks more frequent and harder to detect. By targeting cloud environments and leveraging human vulnerabilities, LUCR-3 compromises identity providers (IDPs) and uses sophisticated techniques to breach organizations. Before we begin, I wanted\",\"inLanguage\":\"en-GB\",\"isPartOf\":{\"@id\":\"http:\\\/\\\/3.10.118.248\\\/#website\"},\"breadcrumb\":{\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?p=1235#breadcrumblist\"},\"author\":{\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?author=2#author\"},\"creator\":{\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?author=2#author\"},\"datePublished\":\"2024-10-20T18:39:43+01:00\",\"dateModified\":\"2024-10-20T18:39:43+01:00\"},{\"@type\":\"WebSite\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/#website\",\"url\":\"http:\\\/\\\/3.10.118.248\\\/\",\"name\":\"Nocturnalknight's Lair\",\"description\":\"Observations of a Random Wanderer!\",\"inLanguage\":\"en-GB\",\"publisher\":{\"@id\":\"http:\\\/\\\/3.10.118.248\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Scattered Spider Attacks: Tips for SaaS Security - Nocturnalknight's Lair","description":"As cloud adoption soars, threat groups like LUCR-3 Scattered Spider and Oktapus are mastering new ways to exploit identity management systems(IAMs), making these attacks more frequent and harder to detect. By targeting cloud environments and leveraging human vulnerabilities, LUCR-3 compromises identity providers (IDPs) and uses sophisticated techniques to breach organizations. Before we begin, I wanted","canonical_url":"http:\/\/3.10.118.248\/?p=1235","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"http:\/\/3.10.118.248\/?p=1235#blogposting","name":"Scattered Spider Attacks: Tips for SaaS Security - Nocturnalknight's Lair","headline":"Scattered Spider Attacks: Tips for SaaS Security","author":{"@id":"http:\/\/3.10.118.248\/?author=2#author"},"publisher":{"@id":"http:\/\/3.10.118.248\/#organization"},"image":{"@type":"ImageObject","url":"http:\/\/3.10.118.248\/wp-content\/uploads\/2024\/10\/A_dynamic_16_9_hero_image_resized-min.png","@id":"http:\/\/3.10.118.248\/?p=1235\/#articleImage","width":1792,"height":1024},"datePublished":"2024-10-20T18:39:43+01:00","dateModified":"2024-10-20T18:39:43+01:00","inLanguage":"en-GB","mainEntityOfPage":{"@id":"http:\/\/3.10.118.248\/?p=1235#webpage"},"isPartOf":{"@id":"http:\/\/3.10.118.248\/?p=1235#webpage"},"articleSection":"Cloud Security, IAM, Information Security, SaaS, Cloud Security, IAM, information security, saas, Scattered Spider"},{"@type":"BreadcrumbList","@id":"http:\/\/3.10.118.248\/?p=1235#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"http:\/\/3.10.118.248#listItem","position":1,"name":"Home","item":"http:\/\/3.10.118.248","nextItem":{"@type":"ListItem","@id":"http:\/\/3.10.118.248\/?cat=81#listItem","name":"Information Security"}},{"@type":"ListItem","@id":"http:\/\/3.10.118.248\/?cat=81#listItem","position":2,"name":"Information Security","item":"http:\/\/3.10.118.248\/?cat=81","nextItem":{"@type":"ListItem","@id":"http:\/\/3.10.118.248\/?cat=185#listItem","name":"Cloud Security"},"previousItem":{"@type":"ListItem","@id":"http:\/\/3.10.118.248#listItem","name":"Home"}},{"@type":"ListItem","@id":"http:\/\/3.10.118.248\/?cat=185#listItem","position":3,"name":"Cloud Security","item":"http:\/\/3.10.118.248\/?cat=185","nextItem":{"@type":"ListItem","@id":"http:\/\/3.10.118.248\/?p=1235#listItem","name":"Scattered Spider Attacks: Tips for SaaS Security"},"previousItem":{"@type":"ListItem","@id":"http:\/\/3.10.118.248\/?cat=81#listItem","name":"Information Security"}},{"@type":"ListItem","@id":"http:\/\/3.10.118.248\/?p=1235#listItem","position":4,"name":"Scattered Spider Attacks: Tips for SaaS Security","previousItem":{"@type":"ListItem","@id":"http:\/\/3.10.118.248\/?cat=185#listItem","name":"Cloud Security"}}]},{"@type":"Organization","@id":"http:\/\/3.10.118.248\/#organization","name":"Nocturnalknight's Lair","description":"Observations of a Random Wanderer!","url":"http:\/\/3.10.118.248\/","logo":{"@type":"ImageObject","url":"http:\/\/3.10.118.248\/wp-content\/uploads\/2026\/08\/cropped-Ram-Profile.avif","@id":"http:\/\/3.10.118.248\/?p=1235\/#organizationLogo"},"image":{"@id":"http:\/\/3.10.118.248\/?p=1235\/#organizationLogo"},"sameAs":["https:\/\/x.com\/nocturnalknight","https:\/\/www.linkedin.com\/in\/nocturnalknight\/"]},{"@type":"Person","@id":"http:\/\/3.10.118.248\/?author=2#author","url":"http:\/\/3.10.118.248\/?author=2","name":"Ramkumar Sundarakalatharan","image":{"@type":"ImageObject","@id":"http:\/\/3.10.118.248\/?p=1235#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/818bc4a4d5681de6957f83aca2601d598459bf37a0a8b17d5abb1a889e2b9298?s=96&d=mm&r=g","width":96,"height":96,"caption":"Ramkumar Sundarakalatharan"}},{"@type":"WebPage","@id":"http:\/\/3.10.118.248\/?p=1235#webpage","url":"http:\/\/3.10.118.248\/?p=1235","name":"Scattered Spider Attacks: Tips for SaaS Security - Nocturnalknight's Lair","description":"As cloud adoption soars, threat groups like LUCR-3 Scattered Spider and Oktapus are mastering new ways to exploit identity management systems(IAMs), making these attacks more frequent and harder to detect. By targeting cloud environments and leveraging human vulnerabilities, LUCR-3 compromises identity providers (IDPs) and uses sophisticated techniques to breach organizations. Before we begin, I wanted","inLanguage":"en-GB","isPartOf":{"@id":"http:\/\/3.10.118.248\/#website"},"breadcrumb":{"@id":"http:\/\/3.10.118.248\/?p=1235#breadcrumblist"},"author":{"@id":"http:\/\/3.10.118.248\/?author=2#author"},"creator":{"@id":"http:\/\/3.10.118.248\/?author=2#author"},"datePublished":"2024-10-20T18:39:43+01:00","dateModified":"2024-10-20T18:39:43+01:00"},{"@type":"WebSite","@id":"http:\/\/3.10.118.248\/#website","url":"http:\/\/3.10.118.248\/","name":"Nocturnalknight's Lair","description":"Observations of a Random Wanderer!","inLanguage":"en-GB","publisher":{"@id":"http:\/\/3.10.118.248\/#organization"}}]},"og:locale":"en_GB","og:site_name":"Nocturnalknight's Lair - Observations of a Random Wanderer!","og:type":"article","og:title":"Scattered Spider Attacks: Tips for SaaS Security - Nocturnalknight's Lair","og:description":"As cloud adoption soars, threat groups like LUCR-3 Scattered Spider and Oktapus are mastering new ways to exploit identity management systems(IAMs), making these attacks more frequent and harder to detect. By targeting cloud environments and leveraging human vulnerabilities, LUCR-3 compromises identity providers (IDPs) and uses sophisticated techniques to breach organizations. Before we begin, I wanted","og:url":"http:\/\/3.10.118.248\/?p=1235","article:published_time":"2024-10-20T13:09:43+00:00","article:modified_time":"2024-10-20T13:09:43+00:00","twitter:card":"summary_large_image","twitter:site":"@nocturnalknight","twitter:title":"Scattered Spider Attacks: Tips for SaaS Security - Nocturnalknight's Lair","twitter:description":"As cloud adoption soars, threat groups like LUCR-3 Scattered Spider and Oktapus are mastering new ways to exploit identity management systems(IAMs), making these attacks more frequent and harder to detect. By targeting cloud environments and leveraging human vulnerabilities, LUCR-3 compromises identity providers (IDPs) and uses sophisticated techniques to breach organizations. Before we begin, I wanted","twitter:creator":"@nocturnalknight"},"aioseo_meta_data":{"post_id":"1235","title":null,"description":null,"keywords":null,"keyphrases":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_custom_url":null,"og_image_custom_fields":null,"og_image_url":null,"og_image_width":null,"og_image_height":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_image_url":null,"twitter_title":null,"twitter_description":null,"schema_type":"default","schema_type_options":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"limit_modified_date":false,"ai":null,"breadcrumb_settings":null,"seo_analyzer_scan_date":null,"created":"2026-08-19 12:04:12","updated":"2026-08-19 12:04:12"},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"http:\/\/3.10.118.248\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"http:\/\/3.10.118.248\/?cat=81\" title=\"Information Security\">Information Security<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"http:\/\/3.10.118.248\/?cat=185\" title=\"Cloud Security\">Cloud Security<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tScattered Spider Attacks: Tips for SaaS Security\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"http:\/\/3.10.118.248"},{"label":"Information Security","link":"http:\/\/3.10.118.248\/?cat=81"},{"label":"Cloud Security","link":"http:\/\/3.10.118.248\/?cat=185"},{"label":"Scattered Spider Attacks: Tips for SaaS Security","link":"http:\/\/3.10.118.248\/?p=1235"}],"amp_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"http:\/\/3.10.118.248\/index.php?rest_route=\/wp\/v2\/posts\/1235","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/3.10.118.248\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/3.10.118.248\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/3.10.118.248\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/3.10.118.248\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1235"}],"version-history":[{"count":0,"href":"http:\/\/3.10.118.248\/index.php?rest_route=\/wp\/v2\/posts\/1235\/revisions"}],"wp:attachment":[{"href":"http:\/\/3.10.118.248\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1235"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/3.10.118.248\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1235"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/3.10.118.248\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1235"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}