Scattered Spider, a sophisticated cyber threat group known for aggressive social engineering and targeted phishing, is broadening its scope, notably targeting aviation alongside enterprise environments. During a targeted investigation, Check Point researchers identified approximately 500 domains that follow Scattered Spider’s known naming conventions, indicating potential phishing infrastructure either in use or prepared for future attacks. Scattered Spider’s phishing domain patterns provide actionable insights to proactively counter threats from the notorious cyber group responsible for recent airline attacks. Check Point Research has uncovered specific phishing domain indicators, helping enterprises and aviation companies proactively defend against this emerging threat. Check Point Research has identified a consistent pattern in the phishing infrastructure registered by Scattered Spider. In a significant escalation, recent media reports and intelligence advisories have linked Scattered Spider to cyberattacks on major airlines, notably the July 2025 data breach affecting six million Qantas customers. Their social engineering methods include targeted phishing, SIM swapping, multi-factor authentication (MFA) fatigue attacks, and phone impersonation tactics. Cybersecurity analysts noted tactics such as MFA fatigue and voice phishing (vishing), closely matching Scattered Spider’s known methods.
This Cyber News was published on cybersecuritynews.com. Publication date: Tue, 08 Jul 2025 07:00:15 +0000