In light of the recent high-profile attacks on US and UK retail, we’re hosting this webinar on UNC3944, aka Scattered Spider. Get insight on the actor and expert advice on hardening your enterprise.
From late 2024 through early 2025, Google Threat Intelligence Group observed a decline in activity conducted by certain threat clusters, such as UNC3944 and UNC3786, associated with the underground community known as "The Com." Some of these threat clusters, including UNC3944, overlap with public reporting on Scattered Spider, which may be behind recent ransomware attacks impacting the UK retail sector. We recently observed activity using similar TTPs impacting US organizations operating in multiple sectors including retail. Preliminary analysis indicates that there are TTP overlaps with prior activity originating from threat clusters associated with The Com, but attribution to specific threat clusters is still ongoing at this time.
Threat actors associated with The Com have historically been aggressive, creative, and particularly effective at circumventing mature security programs. They have had a lot of success with social engineering and leveraging third parties to gain entry to their targets. Mandiant has provided a hardening guide based on our experience with more details on their tactics and steps organizations can take to defend themselves.
This webinar will provide critical insights and actionable recommendations to defend against the evolving tactics of UNC3944 and related groups. Drawing from extensive experience responding to this actor, we will prioritize key areas for proactive hardening across your enterprise, including:
*Enhancing Identity Security
*Fortifying Endpoints & Cloud Resources
*Strengthening Network Defenses
*Boosting Monitoring and Detection
*Cultivating Social Engineering Awareness