Scattered Spider Q2 2025: vCenter Unmanaged VM ntds.dit Dumping, Chisel/Teleport/Pinggy Tunneling, S3 Browser Exfiltration, and Email Transport Rule Hijacking

CrowdStrike Services documented in a report published on CrowdStrike Services Scattered Spider's Q2 2025 escalation targeting US insurance, US/UK retail, and — in late June 2025 — US airlines, with TTPs consistent across all sectors. The adversary's primary objective is ESXi ransomware deployment; when contained before encryption, double extortion via stolen data threats is used as the fallback monetization strategy.

Initial Access and Identity Provider Compromise: Entra ID, SSO, VDI via Help Desk Vishing

In almost all 2025 incidents, Scattered Spider used voice-based phishing (vishing) against IT help desks, accurately answering verification questions while impersonating legitimate employees to obtain password and MFA resets for Microsoft Entra ID, SSO, and VDI accounts. From these compromised identity provider accounts, the adversary pivots into integrated SaaS applications, searching for network architecture diagrams, VPN documentation, and plaintext credential files to enable further lateral movement. Active Directory reconnaissance used ADExplorer, ADRecon.ps1, and the Get-ADUser PowerShell cmdlet on on-premises systems.

VMware vCenter Abuse: Unmanaged VM Creation and ntds.dit Extraction

A key TTP observed across multiple 2025 incidents: the adversary uses VMware vCenter access to create unmanaged (rogue) virtual machines, then attaches domain controller VM disks to these unmanaged VMs to dump the Active Directory database (ntds.dit) — obtaining all domain password hashes without requiring a live domain controller connection. Protocol-tunneling and proxy tools installed on vCenter and adversary-controlled VMs include Chisel (configured to communicate with trycloudflare[.]com subdomains), MobaXterm, Ngrok, Pinggy, Rsocx, and Teleport — providing persistent, obfuscated C2 channels that blend with cloud service traffic.

Email Transport Rule Manipulation and S3 Browser Data Exfiltration

To suppress account security notifications, the adversary performed manual hard-delete, soft-delete, and MoveToDeletedItems operations on security alert emails, and created Exchange transport rules via Set-TransportRule to redirect notifications to adversary-controlled addresses — in one documented case, a googlemail[.]com address. Data exfiltration used S3 Browser to enumerate victim AWS S3 buckets (triggering CloudTrail events ListBuckets and ListObjects) and transfer data to remote adversary-controlled S3 buckets. Primary ransomware targets are VMware ESXi environments; additional consistent targets include cloud identity providers (Entra ID, AWS IAM, Okta), PAM systems, VPN solutions, backup systems, and help desk personnel.

Detection coverage

Read the full analysis on IntelFusions