New findings from Lares Labs underscore the importance of realistic threat emulation exercises that mirror the sophisticated tactics of the Scattered Spider APT group.
By integrating real-world incident data into controlled simulations, organizations can proactively assess defenses across networks, endpoints, and cloud environments, bolstering resilience against advanced persistent threats.
Lares’s research centers on recreating the full attack lifecycle employed by Scattered Spider from initial access via social engineering through lateral movement, privilege escalation, and eventual exfiltration.
Unlike traditional red teaming, which often focuses on isolated technical exploits, Lares combines ethical hacking, tailored social engineering, and threat emulation to replicate the subtle interplay of human manipulation and technical tradecraft observed in recent high-profile breaches.
Scattered Spider Attack Across Industries
Scattered Spider, active since May 2022, has targeted telecommunications, BPO, hospitality, retail, healthcare, and aviation sectors. The group’s young, English-speaking operatives leverage SIM swapping, phishing, and push-bombing to circumvent MFA, then install legitimate remote access tools for persistence.
Their operations also include bespoke cloud credential theft using utilities like AWS console or MicroBurst and Bring Your Own Vulnerable Driver (BYOVD) attacks, deploying Microsoft-signed vulnerable drivers such as POORTRY via a custom loader named STONESTOP to disable endpoint defenses.
Lares Lab simulations begin with open-source reconnaissance, harvesting corporate data from LinkedIn and breached credential repositories, then crafting realistic phishing lures through look-alike domains (e.g., targetsname-sso[.]com).
Participants experience the pressure of repeated MFA pushes and SIM swap scenarios, forcing defenders to react in real time. Subsequent stages emulate privilege escalation tactics, including ADCS abuse, DACL misconfiguration exploitation, and LSASS or NTDS.dit credential dumping via Mimikatz and Jetcretz.

During lateral movement exercises, defenders confront genuine SSO session hijacking and Proxifier-linked traffic redirection, mirroring Scattered Spider’s use of cloud-based pivot points.
In cloud environments, simulations exploit IAM misconfigurations such as overly permissive assume-role policies to traverse EC2 instances and compromise additional user accounts. These exercises challenge teams to detect anomalous API calls and unusual credential usage patterns.
Exfiltration scenarios utilize encrypted messaging platforms like Telegram for small, high-value files and tools like Rclone or MEGAsync for bulk data transfer to attacker-controlled cloud storage.
Participants must identify stealthy data flows and intercept covert channels, refining both monitoring rules and incident response playbooks.
Lares’s approach delivers actionable intelligence: customized debriefs highlight detection blind spots, misaligned processes, and training gaps. Security teams leave with prioritized recommendations, ranging from tightening MFA policies and hardening AD configurations to refining cloud security posture and enhancing phishing resilience.
Other common tools, such as ManageEngine and Amazon Web Services inventory, always aim, whenever possible, to use legitimate tools native to the target environment to reduce detection by security solutions and maintain a low-profile attack.

As Scattered Spider’s tactics continue evolving, organizations face a dual challenge: bridging technology gaps and fortifying human defenses.
Lares’s research demonstrates that emulating real-world adversaries within a safe, controlled environment accelerates preparedness more effectively than theoretical exercises.
By testing controls against the actual TTPs of APT groups, such as Scattered Spider, enterprises shift from a reactive to a proactive stance, ultimately reducing dwell time and mitigating potential financial and reputational impacts.
Lares Labs recommends that organizations adopt regular threat emulation cycles, updating scenarios with the latest intelligence on groups such as Scattered Spider, UNC3944, Octo Tempest, and others. Through continuous adversarial collaboration and iterative testing, defenders can ensure their security posture evolves as rapidly as the threats they face.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.
