Engage Report: SCATTERED SPIDER Ransomware Operations in the Cloud

  1. Compromise a privileged account within the victim tenant (e.g., Global Administrator or Security Administrator).
  2. Establish inbound synchronization from an attacker-controlled tenant to the victim tenant.
  3. Provision malicious accounts within the victim tenant as needed.
  4. Maintain persistence and potentially move laterally across connected tenants.