A Scattered Spider member was indicted. Microsoft’s GDID went to trial.
Summary
A recent criminal complaint against a Scattered Spider member details the use of Microsoft's Global Device Identifier (GDID). This persistent identifier tied to a Windows installation was crucial in correlating the suspect's activity with ngrok signup and other telemetry, aiding investigators in identifying him. The indictment has raised privacy concerns regarding Microsoft's data collection practices.
IFF Assessment
The article details how a specific technical identifier (GDID) was used by law enforcement to track and indict a member of a cybercrime group, representing a win for defenders in attributing malicious activity.
Defender Context
This case highlights the importance of understanding and correlating various data points, including device identifiers and service logs, for attributing malicious activity. Defenders should be aware of how such persistent identifiers can be leveraged in investigations and consider their own data collection and retention policies.