{"id":116742,"date":"2025-07-18T11:00:22","date_gmt":"2025-07-18T11:00:22","guid":{"rendered":"https:\/\/cybersecuritynews.com\/?p=116742"},"modified":"2025-07-18T11:00:28","modified_gmt":"2025-07-18T11:00:28","slug":"microsoft-details-scattered-spider-ttps","status":"publish","type":"post","link":"https:\/\/cybersecuritynews.com\/microsoft-details-scattered-spider-ttps\/","title":{"rendered":"Microsoft Details Scattered Spider TTPs Observed in Recent Attack Chains"},"content":{"rendered":"\n<p>In mid-2025, a new surge of targeted intrusions, attributed to the threat group known variously as Scattered Spider, Octo Tempest, UNC3944, Muddled Libra, and 0ktapus, began impacting multiple industries.<\/p>\n\n\n\n<p>Initially identified by unusual SMS-based <a href=\"https:\/\/cybersecuritynews.com\/evolving-phishing-campaigns\/\" target=\"_blank\" rel=\"noreferrer noopener\">phishing campaigns<\/a> leveraging adversary-in-the-middle (AiTM) domains, these operators have since refined their approach to combine sophisticated social engineering with stealthy network exploitation.<\/p>\n\n\n\n<p>Their primary goal remains financial gain through extortion or ransomware deployment, often after months of reconnaissance and credential harvesting.<\/p>\n\n\n\n<p>Microsoft analysts <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/07\/16\/protecting-customers-from-octo-tempest-attacks-across-multiple-industries\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">noted<\/a> that these campaigns typically commence with a carefully crafted spear-phishing message or direct service-desk impersonation via phone, email, or messaging platforms.<\/p>\n\n\n\n<p>Once initial access is achieved, <a href=\"https:\/\/cybersecuritynews.com\/scattered-spider-hackers-aviation\/\" target=\"_blank\" rel=\"noreferrer noopener\">Scattered Spider<\/a> pivots rapidly to reconnaissance, enumeration of Active Directory attributes, and credential dumping, frequently using tools like Mimikatz and AADInternals.<\/p>\n\n\n\n<p>Concurrently, the attackers establish persistence via trusted backdoors and leverage ngrok or Chisel tunnels to maintain covert communications with compromised assets.<\/p>\n\n\n\n<p>Shortly after these initial moves, Microsoft researchers observed the deployment of DragonForce ransomware, with a distinct focus on <a href=\"https:\/\/cybersecuritynews.com\/vmware-esxi-authentication-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">VMware ESX<\/a> hypervisor environments.<\/p>\n\n\n\n<p>This choice allows the threat actors to encrypt entire datastores, maximizing operational disruption and ransom demands.<\/p>\n\n\n\n<p>Complicating defenses further, Scattered Spider\u2019s recent tactics blend on-premises and cloud identity exploitation, attacking critical Entra Connect servers to cross domain boundaries.<\/p>\n\n\n\n<p>Such hybrid strikes underline the group\u2019s evolution from purely cloud-focused assaults to full-spectrum intrusions.<\/p>\n\n\n\n<p>Detection of these tactics, techniques, and procedures (TTPs) has been thoroughly mapped across Microsoft Defender\u2019s <a href=\"https:\/\/cybersecuritynews.com\/xdr-ciso-investment-trends\/\" target=\"_blank\" rel=\"noreferrer noopener\">XDR ecosystem<\/a>.<\/p>\n\n\n\n<p>From unusual password reset alerts in virtual machines (MDC) to detection of DCSync attempts (MDI) and suspicious elevate-access operations (MDC), defenders can monitor high-fidelity signals across endpoints, identities, and cloud workloads.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgXeaeUX5Tu6iAlQguML4DzibB4CVAUk094TfNlWoTtCWWO8bnP79CCZ8CIbkYbUi0ZJXyr76zuUhHSK2_UAI40rmLYEGEghGfYAL09NtGztUU3KvwpVPuLrjmJGupdptS86zc7iYpl693f-k0sxv85u3dA6ZQPKKPQVLaqT7fY48kLXBCzh-YQu7XQ2fo\/s16000\/Attack%20path%20(Source%20-%20Microsoft).webp\" alt=\"\" \/><figcaption class=\"wp-element-caption\">Attack path (Source &#8211; Microsoft)<\/figcaption><\/figure><\/div>\n\n\n<h2 class=\"wp-block-heading\"><strong>Persistence Tactics: Establishing a Covert Foothold<\/strong><\/h2>\n\n\n\n<p>A critical subtopic in Scattered Spider\u2019s arsenal is its use of ADFS persistent backdoors to guarantee long-term access.<\/p>\n\n\n\n<p>Once administrative privileges are obtained, the group deploys custom scripts that modify the ADFS configuration database, injecting malicious service hooks.<\/p>\n\n\n\n<p>These hooks execute automatically upon user authentication, granting attackers elevated privileges without further credential prompts.<\/p>\n\n\n\n<p>Microsoft analysts identified the following <a href=\"https:\/\/cybersecuritynews.com\/hackers-actively-exploiting-powershell\/\" target=\"_blank\" rel=\"noreferrer noopener\">PowerShell<\/a> snippet within affected environments, used to implant the backdoor:-<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Import-Module AADInternals  \n$cred = Get-Credential  \nSet-AdfsProperties -AutoCertificateRollover $false  \nAdd-AdfsServicePrincipalName -Principal $cred.UserName -ServicePrimaryRefreshToken $true  <\/code><\/pre>\n\n\n\n<p>This code disables automatic certificate renewal to prevent inadvertent removal of the backdoor and registers a service principal name linked to attacker-controlled credentials.<\/p>\n\n\n\n<p>By leveraging entra ID APIs, the adversary ensures that any authentication event triggers a silent elevation of privileges, effectively bypassing multifactor authentication checks.<\/p>\n\n\n\n<p>Continued vigilance through advanced hunting queries for anomalous ADFS configuration changes enables SOC teams to detect and remediate these persistence mechanisms before attackers can fully exploit them.<\/p>\n\n\n\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Boost detection, reduce alert fatigue, accelerate response; all with an interactive sandbox built for security teams -&gt;\u00a0<a href=\"https:\/\/any.run\/demo?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=top3_ciso_challenges&amp;utm_content=demo_1&amp;utm_term=160725\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try ANY.RUN Now<\/a><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In mid-2025, a new surge of targeted intrusions, attributed to the threat group known variously as Scattered Spider, Octo Tempest, UNC3944, Muddled Libra, and 0ktapus, began impacting multiple industries. Initially identified by unusual SMS-based phishing campaigns leveraging adversary-in-the-middle (AiTM) domains, these operators have since refined their approach to combine sophisticated social engineering with stealthy network [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":116771,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjCfo6GX3cjoqtFlmAbApu002wx00PRbo4QZVh8YIBtPiVGjjNlvsiEvIPbNNtZEcl3rBtu7e7k2YsBLbz7TSwAllN_GjA6k5DLpqYSov8gWjoUh_sKC2ONNuS5js8y9nogm5O6Ppo0QXnBrNQbzypWxc4tGGbozMcTvhAvJH7cqPRUi-HPBkvvJpOGGyM\/s16000\/Microsoft%20Details%20Scattered%20Spider%20TTPs%20Observed%20in%20Recent%20Attack%20Chains.webp","fifu_image_alt":"","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11,48],"tags":[149,151],"class_list":{"0":"post-116742","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-cyber-security-news","8":"category-threats","9":"tag-cyber-security","10":"tag-cyber-security-news"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v25.7.1 (Yoast SEO v25.7) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Microsoft Details Scattered Spider TTPs Observed in Recent Attack Chains<\/title>\n<meta name=\"description\" content=\"Scattered Spider resurges in 2025 with SMS phishing, social engineering, and stealthy exploits to deploy ransomware across key industries.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cybersecuritynews.com\/microsoft-details-scattered-spider-ttps\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Microsoft Details Scattered Spider TTPs Observed in Recent Attack Chains\" \/>\n<meta property=\"og:description\" content=\"Scattered Spider resurges in 2025 with SMS phishing, social engineering, and stealthy exploits to deploy ransomware across key industries.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cybersecuritynews.com\/microsoft-details-scattered-spider-ttps\/\" \/>\n<meta property=\"og:site_name\" content=\"Cyber Security News\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hackingtutorialsandnews\" \/>\n<meta property=\"article:published_time\" content=\"2025-07-18T11:00:22+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-07-18T11:00:28+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjCfo6GX3cjoqtFlmAbApu002wx00PRbo4QZVh8YIBtPiVGjjNlvsiEvIPbNNtZEcl3rBtu7e7k2YsBLbz7TSwAllN_GjA6k5DLpqYSov8gWjoUh_sKC2ONNuS5js8y9nogm5O6Ppo0QXnBrNQbzypWxc4tGGbozMcTvhAvJH7cqPRUi-HPBkvvJpOGGyM\/s16000\/Microsoft%20Details%20Scattered%20Spider%20TTPs%20Observed%20in%20Recent%20Attack%20Chains.webp\" \/><meta property=\"og:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjCfo6GX3cjoqtFlmAbApu002wx00PRbo4QZVh8YIBtPiVGjjNlvsiEvIPbNNtZEcl3rBtu7e7k2YsBLbz7TSwAllN_GjA6k5DLpqYSov8gWjoUh_sKC2ONNuS5js8y9nogm5O6Ppo0QXnBrNQbzypWxc4tGGbozMcTvhAvJH7cqPRUi-HPBkvvJpOGGyM\/s16000\/Microsoft%20Details%20Scattered%20Spider%20TTPs%20Observed%20in%20Recent%20Attack%20Chains.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1600\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Tushar Subhra Dutta\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjCfo6GX3cjoqtFlmAbApu002wx00PRbo4QZVh8YIBtPiVGjjNlvsiEvIPbNNtZEcl3rBtu7e7k2YsBLbz7TSwAllN_GjA6k5DLpqYSov8gWjoUh_sKC2ONNuS5js8y9nogm5O6Ppo0QXnBrNQbzypWxc4tGGbozMcTvhAvJH7cqPRUi-HPBkvvJpOGGyM\/s16000\/Microsoft%20Details%20Scattered%20Spider%20TTPs%20Observed%20in%20Recent%20Attack%20Chains.webp\" \/>\n<meta name=\"twitter:creator\" content=\"@The_Cyber_News\" \/>\n<meta name=\"twitter:site\" content=\"@The_Cyber_News\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Tushar Subhra Dutta\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Microsoft Details Scattered Spider TTPs Observed in Recent Attack Chains","description":"Scattered Spider resurges in 2025 with SMS phishing, social engineering, and stealthy exploits to deploy ransomware across key industries.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cybersecuritynews.com\/microsoft-details-scattered-spider-ttps\/","og_locale":"en_US","og_type":"article","og_title":"Microsoft Details Scattered Spider TTPs Observed in Recent Attack Chains","og_description":"Scattered Spider resurges in 2025 with SMS phishing, social engineering, and stealthy exploits to deploy ransomware across key industries.","og_url":"https:\/\/cybersecuritynews.com\/microsoft-details-scattered-spider-ttps\/","og_site_name":"Cyber Security News","article_publisher":"https:\/\/www.facebook.com\/Hackingtutorialsandnews","article_published_time":"2025-07-18T11:00:22+00:00","article_modified_time":"2025-07-18T11:00:28+00:00","og_image":[{"url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjCfo6GX3cjoqtFlmAbApu002wx00PRbo4QZVh8YIBtPiVGjjNlvsiEvIPbNNtZEcl3rBtu7e7k2YsBLbz7TSwAllN_GjA6k5DLpqYSov8gWjoUh_sKC2ONNuS5js8y9nogm5O6Ppo0QXnBrNQbzypWxc4tGGbozMcTvhAvJH7cqPRUi-HPBkvvJpOGGyM\/s16000\/Microsoft%20Details%20Scattered%20Spider%20TTPs%20Observed%20in%20Recent%20Attack%20Chains.webp","type":"","width":"","height":""},{"width":1600,"height":900,"url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjCfo6GX3cjoqtFlmAbApu002wx00PRbo4QZVh8YIBtPiVGjjNlvsiEvIPbNNtZEcl3rBtu7e7k2YsBLbz7TSwAllN_GjA6k5DLpqYSov8gWjoUh_sKC2ONNuS5js8y9nogm5O6Ppo0QXnBrNQbzypWxc4tGGbozMcTvhAvJH7cqPRUi-HPBkvvJpOGGyM\/s16000\/Microsoft%20Details%20Scattered%20Spider%20TTPs%20Observed%20in%20Recent%20Attack%20Chains.webp","type":"image\/jpeg"}],"author":"Tushar Subhra Dutta","twitter_card":"summary_large_image","twitter_image":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjCfo6GX3cjoqtFlmAbApu002wx00PRbo4QZVh8YIBtPiVGjjNlvsiEvIPbNNtZEcl3rBtu7e7k2YsBLbz7TSwAllN_GjA6k5DLpqYSov8gWjoUh_sKC2ONNuS5js8y9nogm5O6Ppo0QXnBrNQbzypWxc4tGGbozMcTvhAvJH7cqPRUi-HPBkvvJpOGGyM\/s16000\/Microsoft%20Details%20Scattered%20Spider%20TTPs%20Observed%20in%20Recent%20Attack%20Chains.webp","twitter_creator":"@The_Cyber_News","twitter_site":"@The_Cyber_News","twitter_misc":{"Written by":"Tushar Subhra Dutta","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/cybersecuritynews.com\/microsoft-details-scattered-spider-ttps\/#article","isPartOf":{"@id":"https:\/\/cybersecuritynews.com\/microsoft-details-scattered-spider-ttps\/"},"author":{"name":"Tushar Subhra Dutta","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/7eb7d8d026aa5dd566f134d4def5c05c"},"headline":"Microsoft Details Scattered Spider TTPs Observed in Recent Attack Chains","datePublished":"2025-07-18T11:00:22+00:00","dateModified":"2025-07-18T11:00:28+00:00","mainEntityOfPage":{"@id":"https:\/\/cybersecuritynews.com\/microsoft-details-scattered-spider-ttps\/"},"wordCount":457,"publisher":{"@id":"https:\/\/cybersecuritynews.com\/#organization"},"image":{"@id":"https:\/\/cybersecuritynews.com\/microsoft-details-scattered-spider-ttps\/#primaryimage"},"thumbnailUrl":"https:\/\/i3.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjCfo6GX3cjoqtFlmAbApu002wx00PRbo4QZVh8YIBtPiVGjjNlvsiEvIPbNNtZEcl3rBtu7e7k2YsBLbz7TSwAllN_GjA6k5DLpqYSov8gWjoUh_sKC2ONNuS5js8y9nogm5O6Ppo0QXnBrNQbzypWxc4tGGbozMcTvhAvJH7cqPRUi-HPBkvvJpOGGyM\/s16000\/Microsoft%20Details%20Scattered%20Spider%20TTPs%20Observed%20in%20Recent%20Attack%20Chains.webp?w=1600&resize=1600,900&ssl=1","keywords":["cyber security","cyber security news"],"articleSection":["Cyber Security News","Threats"],"inLanguage":"en-US","copyrightYear":"2025","copyrightHolder":{"@id":"https:\/\/cybersecuritynews.com\/#organization"}},{"@type":"WebPage","@id":"https:\/\/cybersecuritynews.com\/microsoft-details-scattered-spider-ttps\/","url":"https:\/\/cybersecuritynews.com\/microsoft-details-scattered-spider-ttps\/","name":"Microsoft Details Scattered Spider TTPs Observed in Recent Attack Chains","isPartOf":{"@id":"https:\/\/cybersecuritynews.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cybersecuritynews.com\/microsoft-details-scattered-spider-ttps\/#primaryimage"},"image":{"@id":"https:\/\/cybersecuritynews.com\/microsoft-details-scattered-spider-ttps\/#primaryimage"},"thumbnailUrl":"https:\/\/i3.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjCfo6GX3cjoqtFlmAbApu002wx00PRbo4QZVh8YIBtPiVGjjNlvsiEvIPbNNtZEcl3rBtu7e7k2YsBLbz7TSwAllN_GjA6k5DLpqYSov8gWjoUh_sKC2ONNuS5js8y9nogm5O6Ppo0QXnBrNQbzypWxc4tGGbozMcTvhAvJH7cqPRUi-HPBkvvJpOGGyM\/s16000\/Microsoft%20Details%20Scattered%20Spider%20TTPs%20Observed%20in%20Recent%20Attack%20Chains.webp?w=1600&resize=1600,900&ssl=1","datePublished":"2025-07-18T11:00:22+00:00","dateModified":"2025-07-18T11:00:28+00:00","description":"Scattered Spider resurges in 2025 with SMS phishing, social engineering, and stealthy exploits to deploy ransomware across key industries.","breadcrumb":{"@id":"https:\/\/cybersecuritynews.com\/microsoft-details-scattered-spider-ttps\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cybersecuritynews.com\/microsoft-details-scattered-spider-ttps\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/microsoft-details-scattered-spider-ttps\/#primaryimage","url":"https:\/\/i3.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjCfo6GX3cjoqtFlmAbApu002wx00PRbo4QZVh8YIBtPiVGjjNlvsiEvIPbNNtZEcl3rBtu7e7k2YsBLbz7TSwAllN_GjA6k5DLpqYSov8gWjoUh_sKC2ONNuS5js8y9nogm5O6Ppo0QXnBrNQbzypWxc4tGGbozMcTvhAvJH7cqPRUi-HPBkvvJpOGGyM\/s16000\/Microsoft%20Details%20Scattered%20Spider%20TTPs%20Observed%20in%20Recent%20Attack%20Chains.webp?w=1600&resize=1600,900&ssl=1","contentUrl":"https:\/\/i3.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjCfo6GX3cjoqtFlmAbApu002wx00PRbo4QZVh8YIBtPiVGjjNlvsiEvIPbNNtZEcl3rBtu7e7k2YsBLbz7TSwAllN_GjA6k5DLpqYSov8gWjoUh_sKC2ONNuS5js8y9nogm5O6Ppo0QXnBrNQbzypWxc4tGGbozMcTvhAvJH7cqPRUi-HPBkvvJpOGGyM\/s16000\/Microsoft%20Details%20Scattered%20Spider%20TTPs%20Observed%20in%20Recent%20Attack%20Chains.webp?w=1600&resize=1600,900&ssl=1","width":"1600","height":"900"},{"@type":"BreadcrumbList","@id":"https:\/\/cybersecuritynews.com\/microsoft-details-scattered-spider-ttps\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cybersecuritynews.com\/"},{"@type":"ListItem","position":2,"name":"Microsoft Details Scattered Spider TTPs Observed in Recent Attack Chains"}]},{"@type":"WebSite","@id":"https:\/\/cybersecuritynews.com\/#website","url":"https:\/\/cybersecuritynews.com\/","name":"Cyber Security News","description":"World&#039;s #1 Premier Cybersecurity and Hacking News Portal","publisher":{"@id":"https:\/\/cybersecuritynews.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cybersecuritynews.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/cybersecuritynews.com\/#organization","name":"Cyber Security News","url":"https:\/\/cybersecuritynews.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/logo\/image\/","url":"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2021\/06\/Cyber-security.jpg","contentUrl":"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2021\/06\/Cyber-security.jpg","width":200,"height":200,"caption":"Cyber Security News"},"image":{"@id":"https:\/\/cybersecuritynews.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hackingtutorialsandnews","https:\/\/x.com\/The_Cyber_News","https:\/\/www.linkedin.com\/company\/cybersecurity-news\/"]},{"@type":"Person","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/7eb7d8d026aa5dd566f134d4def5c05c","name":"Tushar Subhra Dutta","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/f8bc0247220c7d4dea6c8b5a77d910613305ead17b13c2a7920b400435a848dd?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f8bc0247220c7d4dea6c8b5a77d910613305ead17b13c2a7920b400435a848dd?s=96&d=mm&r=g","caption":"Tushar Subhra Dutta"},"description":"Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.","url":"https:\/\/cybersecuritynews.com\/author\/tushar\/"}]}},"jetpack_featured_media_url":"https:\/\/i3.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjCfo6GX3cjoqtFlmAbApu002wx00PRbo4QZVh8YIBtPiVGjjNlvsiEvIPbNNtZEcl3rBtu7e7k2YsBLbz7TSwAllN_GjA6k5DLpqYSov8gWjoUh_sKC2ONNuS5js8y9nogm5O6Ppo0QXnBrNQbzypWxc4tGGbozMcTvhAvJH7cqPRUi-HPBkvvJpOGGyM\/s16000\/Microsoft%20Details%20Scattered%20Spider%20TTPs%20Observed%20in%20Recent%20Attack%20Chains.webp?w=1600&resize=1600,900&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/116742","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/comments?post=116742"}],"version-history":[{"count":1,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/116742\/revisions"}],"predecessor-version":[{"id":116770,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/116742\/revisions\/116770"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/media\/116771"}],"wp:attachment":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/media?parent=116742"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/categories?post=116742"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/tags?post=116742"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}