{"id":1118237,"date":"2023-10-01T12:29:47","date_gmt":"2023-10-01T16:29:47","guid":{"rendered":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/uncategorized\/researchers-offer-free-threat-briefings-on-vegas-casino-hackers-computerweekly-com\/"},"modified":"2023-10-01T12:29:47","modified_gmt":"2023-10-01T16:29:47","slug":"researchers-offer-free-threat-briefings-on-vegas-casino-hackers-computerweekly-com","status":"publish","type":"post","link":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/casino\/researchers-offer-free-threat-briefings-on-vegas-casino-hackers-computerweekly-com\/","title":{"rendered":"Researchers offer free threat briefings on Vegas casino hackers &#8211; ComputerWeekly.com"},"content":{"rendered":"<p><p>    Organisations concerned about the possible impact of cyber    attacks originating through the threat actor tracked variously    as Scattered Spider, UNC3944 and 0ktapus can avail themselves    of free worldwide threat briefings available from researchers    at cloud detection and response startup Permiso.  <\/p>\n<p>    Scattered Spider has been active for over a year, but has    achieved renewed prominence in the past few weeks with a series    of damaging cyber attacks on two high-profile operators of    casinos in Las Vegas  MGM Resorts and Caesars Entertainment.  <\/p>\n<p>    Its current modus operandi appears to centre the targeting of    its victims via achieving elevated admin rights     within their cloud tenants and then conducting social    engineering attacks against their IT helpdesks to achieve    persistence.  <\/p>\n<p>        Besides MGM Resorts and Caesars Entertainment, its    victimology includes mostly Fortune 2000 companies in sectors    such as hospitality, manufacturing, retail, software and    telecoms. Its ultimate goal appears to be to steal intellectual    property (IP) and other data for extortion, and it may in some    cases act as an affiliate of     ransomware-as-a-service (RaaS) provider ALPHV\/BlackCat.  <\/p>\n<p>    Permiso, which tracks the threat actor through its P0 Labs team    under the designation LUCR-3, has already supported several    organisations that have been attacked by it.  <\/p>\n<p>    Company co-founder and CEO Jason Martin, who previously worked    at FireEye for a number of years, said Permiso was moved to    offer free briefings because the group is renowned for being    tricky to pin down precisely.  <\/p>\n<p>    LUCR-3 (AKA Scattered Spider) is a threat actor group the P0    Labs team has been following closely in the past year. They are    orchestrating campaigns across cloud environments that touch    not only the cloud hosting providers like [Microsoft] Azure or    AWS [Amazon Web Services], but span across identity providers    and multiple SaaS environments like CRMs [customer relationship    management tools], team collaboration tools, productivity    suites and into CI\/CD [continuous integration\/continuous    delivery] pipelines, explained Martin.  <\/p>\n<p>    They cover their tracks meticulously and can be difficult to    detect, but weve learned a great deal about their TTPs    [tactics, techniques and procedures] and want to freely share    that with the broader community to help organisations defend    against this group.  <\/p>\n<p>    A bit part of Scattered Spiders success to date has been    something of a deficit in many organisations cloud security    postures, particularly as they relate to runtime visibility.    Martin explained that while point-in-time scanning and snapshot    solutions are adept at focusing on the posture of a cloud    environment to ensure resources are configured securely to    protect against rudimentary attacks, detecting attacks against    environments at runtime still presents a significant challenge.  <\/p>\n<p>    This challenge is magnified by Scattered Spider as it easily    and effectively moves across authentication boundaries over the    entire attack surface within the cloud, and moreover, because    much of its access and activity in the cloud is done through    shared credentials like roles and access keys, tracking it to    one individual is difficult, and telling a genuine user apart    from a cyber criminal is much harder, meaning many of Scattered    Spiders attacks have likely gone undetected until its too    late.  <\/p>\n<p>    The use of shared credentials in this way by threat actors is a    clear trend at this point.     As a recent Crowdstrike report revealed, there has been a    significant ramp-up in attempts to steal secret keys and other    credential materials via cloud instance metadata application    programming interfaces (APIs).  <\/p>\n<p>    Interested parties can schedule threat briefings     with the P0 Labs team at their convenience. These will be    led by P0 Labs senior vice-president Ian Ahl, who was formerly    head of advanced practices at Google Cloud-backed Mandiant.  <\/p>\n<p>    Among other things, it will cover the TTPs of the gang, its    role in extortion through data theft, and its recent attacks    against multiple cloud environments. Ahl will also cover how    end-user security teams can develop detections in their own    environments based on Scattered Spiders attack patterns, and    other basic steps they can take to prevent breaches and reduce    dwell times.  <\/p>\n<p><!-- Auto Generated --><\/p>\n<p>Read this article:<\/p>\n<p><a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/www.computerweekly.com\/news\/366553223\/Researchers-offer-free-threat-briefings-on-Vegas-casino-hackers\" title=\"Researchers offer free threat briefings on Vegas casino hackers - ComputerWeekly.com\">Researchers offer free threat briefings on Vegas casino hackers - ComputerWeekly.com<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Organisations concerned about the possible impact of cyber attacks originating through the threat actor tracked variously as Scattered Spider, UNC3944 and 0ktapus can avail themselves of free worldwide threat briefings available from researchers at cloud detection and response startup Permiso. Scattered Spider has been active for over a year, but has achieved renewed prominence in the past few weeks with a series of damaging cyber attacks on two high-profile operators of casinos in Las Vegas MGM Resorts and Caesars Entertainment <a href=\"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/casino\/researchers-offer-free-threat-briefings-on-vegas-casino-hackers-computerweekly-com\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[678864],"tags":[],"class_list":["post-1118237","post","type-post","status-publish","format-standard","hentry","category-casino"],"_links":{"self":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/posts\/1118237"}],"collection":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/comments?post=1118237"}],"version-history":[{"count":0,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/posts\/1118237\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/media?parent=1118237"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/categories?post=1118237"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/tags?post=1118237"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}