Klaviyo, HubSpot, and Pure Storage Hit by Scattered Spider Malware Attacks

Klaviyo, HubSpot, and Pure Storage Hit by Scattered Spider Malware Attacks

Scattered Spider Unleashes Next-Gen Social Engineering on Business Platforms in 2025

A highly adaptive threat group known as Scattered Spider is driving a surge in cyberattacks across enterprise platforms in 2025, deploying increasingly refined tactics that challenge even the most hardened security teams.

First appearing on the radar in 2022, the group has shifted gears, now actively targeting cloud-based marketing and data infrastructure services like Klaviyo, HubSpot, and Pure Storage. These platforms, integral to many organizations’ operations, are being exploited in a wave of precision-targeted attacks that go far beyond standard phishing.

Scattered Spider’s playbook revolves around meticulous social engineering and credential harvesting, with the group focusing on intercepting usernames, passwords, and MFA tokens. What sets them apart is their speed and adaptability: malicious login portals designed to imitate legitimate Okta authentication pages are spun up rapidly, hosted briefly—often no longer than 5 to 30 minutes—then taken down before traditional defenses can react.

Their scope of attack has widened dramatically. In addition to targeting key service providers, Scattered Spider has gone after high-profile companies such as Credit Karma, Nike, Twitter/X, Tinder, Morningstar, Louis Vuitton, T-Mobile, Instacart, and Forbes, among others.

Researchers at Silent Push have traced five unique phishing kits attributed to the group since 2023, with major updates observed as recently as early 2025. These newer kits reflect a shift in infrastructure and strategy, marking a departure from older tools and techniques.

In a notable example, investigators uncovered a phishing domain—klv1.it[.]com—built to mimic Klaviyo’s custom link shortener. The use of Dynamic DNS providers in this instance sidesteps conventional brand detection methods and undermines regex-based URL filtering, illustrating just how agile and evasive Scattered Spider has become.

As the collective’s campaigns evolve, so does the urgency for defenders to rethink domain monitoring, identity protection, and threat detection at the infrastructure level.

Scattered Spider Evolves from Phishing Syndicate to Full-Scale Malware Operation

A new phase in Scattered Spider’s threat evolution has emerged—one that moves beyond high-speed phishing and into deliberate, malware-driven intrusions engineered for persistence and control.

Security analysts have traced a new host operated by the group on the subdomain of it[.]com, signaling a broader campaign footprint (Source: Silent Push). But more troubling is the discovery that Scattered Spider is now pairing social engineering with custom-built malware to establish deeper footholds in compromised environments.

Recent investigations into domains like telnyx-cdn[.]com revealed deployment of a fresh variant of Spectre RAT, a highly customizable remote access trojan that has matured into a capable backdoor framework. Unlike commodity malware, this tool isn’t static—it’s evolving. Researchers noted ongoing development cycles marked by denser obfuscation, expanded remote command functionality, and new persistence mechanisms.

At the heart of Spectre RAT is an intricate command-and-control framework that leverages HTTP with base-level encoded traffic, masking activity in plain sight. Its internal logic is cloaked using a lightweight XOR-based obfuscation algorithm—simple in theory, yet frustratingly effective in dodging static detection tools.

Spectre RAT XOR String Decoder

The malware’s initialization routines lay the groundwork for long-term access, deploying multiple setup routines that ready the infected host for data extraction and remote control. Each incoming instruction from the command server—be it for downloading payloads, terminating processes, or expanding C2 infrastructure—is parsed through a structured system using delimiter-based tokenization (notably the | character), revealing a modular approach to malware execution.

Spectre RAT’s command schema includes a range of capabilities:

  • Command 5: Secure uninstallation and self-deletion
  • Command 13: Dynamically append additional command-and-control nodes

What this means for organizations using platforms like Klaviyo, HubSpot, or Pure Storage is clear: the threat is no longer just about tricking users with phishing emails. It’s about persistent access, system-level compromise, and silent data siphoning under the radar of legacy defenses.

Security teams must urgently revisit their endpoint monitoring and detection strategies, with emphasis on:

  • Flagging suspicious logins or unknown device connections
  • Investigating anomalous account behavior
  • Scanning infrastructure for encoded C2 traffic patterns

The Scattered Spider playbook is shifting—from smash-and-grab to stealth and sustain. The defenders need to shift with it.

More Articles & Posts