DeepSec 2025 Talk: Déjà Vu with Scattered Spider: Are Your SaaS Doors Still Unlocked? – Andi Ahmeti & Abian Morina
LUCR-3 better known as Scattered Spider has surged back in 2025, pivoting its social-engineering playbook from last year’s casino breaches to fresh waves against the insurance, retail and aviation sectors. Within a single June week, LUCR-3 struck several insurers, disrupting airline back-office systems, and a spring ransomware campaign devastated big-box retailers. Still leveraging push-fatigue MFA bombing, SIM-swapping and help-desk impersonation, LUCR-3 now systematically abuses third-party IT providers to fan out across IaaS, SaaS and PaaS estates living off the land in cloud logs to stay invisible until ransom day. Permiso’s P0 Labs has been monitoring LUCR-3’s activities for over two years, documenting their evolving tactics, techniques, and procedures (TTPs). This session will delve into LUCR-3’s latest strategies and provide actionable insights for cloud defenders to detect and mitigate such threats effectively. Andi Ahmeti