Scattered Spider Strikes UK Retail in Coordinated Supply Chain Attacks

Scattered Spider Strikes UK Retail in Coordinated Supply Chain Attacks

Scattered Spider: Precision Strikes on the UK Retail Supply Chain

A rapidly evolving cybercriminal syndicate, known in the intelligence community as Scattered Spider, has pivoted its focus toward the UK retail landscape. This shift marks a deliberate move to exploit seasonal vulnerabilities in supply chain operations, using highly targeted campaigns designed to infiltrate through trusted third-party relationships.

First surfacing in mid-2022, Scattered Spider initially gained notoriety for attacks on telecom and BPO firms. But their recent tactics show a maturation in strategy — moving up the value chain to industries where disruption yields immediate financial reward. UK retail, especially during peak shopping periods, has become a prime target.

What sets this group apart is its hybrid warfare approach: combining deep social engineering with advanced technical exploits. From impersonating IT staff via SMS phishing to hijacking mobile phone numbers through SIM swapping, they capitalize on psychological manipulation as much as technical prowess. A key hallmark of their campaigns is MFA fatigue exploitation — persistently bombarding users with login prompts until one slips through.

Their operations begin with a simple data purchase — employee contact information pulled from public aggregators. That data feeds into a phishing engine designed to bypass human and machine defenses alike. Once inside, Scattered Spider establishes long-term persistence through legitimate remote access tools, ensuring they remain undetected long enough to exfiltrate sensitive data — or, in some cases, drop ransomware.

By mid-2023, Cyberint analysts observed Scattered Spider aligning with the BlackCat/ALPHV ransomware collective, a partnership that significantly raised the stakes. Their targets now span Windows and Linux ecosystems, with VMware ESXi environments squarely in their crosshairs — a clear signal of enterprise-level ambition.

Although there’s been no formal claim for the recent intrusions in the UK retail sector, forensic evidence points strongly to Scattered Spider. The group’s playbook, toolset, and behavioral signatures are unmistakably present.

Of particular concern is their use of custom-built tools to disable defensive technologies. Central to this is POORTRY, a kernel-level driver that shuts down EDR processes by exploiting an old Intel vulnerability (CVE-2015-2291). Signed with a stolen Microsoft certificate, POORTRY is virtually invisible to most detection platforms. Its deployment is orchestrated by STONESTOP, a companion tool that installs and executes the driver with surgical precision.

This technique gives the attackers near-total control over infected systems, allowing them to operate below the radar. It’s not just a breach — it’s a long-term occupation.

Scattered Spider’s involvement in broader affiliate ecosystems, such as the DragonForce model, reflects a shifting ransomware economy: one where roles are specialized, attribution is fragmented, and infrastructure is often white-labeled to avoid detection.

In short, Scattered Spider isn’t just hacking systems — they’re reshaping the way cybercrime is organized and executed.

More Articles & Posts