---
title: "Threat Intel Content Update: 6/10/2025"
description: Tidal Cyber's threat intelligence content updates for the week of 6/10/2025- Scattered Spider, DragonForce Ransomware, Play Ransomware Operation, Qilin Ransomware, “AI Threats” Tag collection 
---

[Threat Intelligence Content Updates ](https://www.tidalcyber.com/threat-updates)

# [Threat Intel Content Update: 6/10/2025](https://www.tidalcyber.com/threat-updates/threat-intel-content-update-6/10/2025)

 Written by [Tidal Cyber](https://www.tidalcyber.com/threat-updates/author/tidal-cyber) | Jun 10, 2025 4:41:18 PM

#### Scattered Spider, DragonForce Ransomware, Play Ransomware Operation, Qilin Ransomware, “AI Threats” Tag collection 

**Threat Content Highlights**

**Threat Objects & Profiles**

Threat Objects, Tags, & Profiles

 

- Technique & Tool relationships update for **[Scattered Spider](https://app.tidalcyber.com/groups/3d77fb6c-cfb4-5563-b0be-7aa1ad535337)** following the latest update to Unit 42’s long-running [“threat assessment” report](https://unit42.paloaltonetworks.com/muddled-libra/) on the group  
    
    - We also updated our “Scattered Spider Ecosystem” curated Threat Profile with this new intelligence, and made it the focus of our **“Trending & Emerging Threats” curated Threat Profile** weekly update. [Recent news reporting](https://www.bleepingcomputer.com/news/security/marks-and-spencer-breach-linked-to-scattered-spider-ransomware-attack/) suggested that elements of Scattered Spider remain active and have been linked to a [DragonForce ransomware](https://app.tidalcyber.com/groups/a58f147b-1f02-427d-a375-c4246335cb20?tab=2) attack on a UK retailer, although the level of direct collaboration between alleged Scattered Spider and DragonForce actors remains unclear.
- Technique & Tool relationships update for the **[Play ransomware](https://app.tidalcyber.com/groups/60f686d0-ae3d-5662-af32-119217dee2a7?tab=2)**** operation**, following a new update to [CISA’s advisory](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-352a) around the group (originally published December 2023)  
    
    - We also added a net-new Playcrypt ESXi Software object based on intel from the updated advisory
- Added a **UNC6040** object following recent reporting that highlighted the group’s use of voice phishing to socially engineer access into victim environments. We’ve highlighted this trending attack vector multiple times in past weeks’ updates.
- Updated our **Qilin ransomware** content following news of new CVE exploit activity linked to this operation
- Three Groups (APT5, Ke3chang, Magic Hound) newly added to our **[“AI Threats” Tag collection](https://app.tidalcyber.com/tags/t/3b73c532-ccfc-4d66-9830-ab76ef1bc47a)** following two [recent](https://cdn.openai.com/threat-intelligence-reports/5f73af09-a3a3-4a55-992e-069237681620/disrupting-malicious-uses-of-ai-june-2025.pdf) [reports](https://www.linkedin.com/posts/unit42_agentserpens-charmingkitten-powerless-ugcPost-7337886287195947009-Q53x)

[View full post](https://www.tidalcyber.com/threat-updates/threat-intel-content-update-6/10/2025)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Tidal Cyber"
  },
  "dateModified" : "2025-06-10T16:41:18.079Z",
  "datePublished" : "2025-06-10T16:41:18Z",
  "headline" : "Threat Intel Content Update: 6/10/2025",
  "image" : {
    "@type" : "ImageObject",
    "height" : 500,
    "url" : "https://21164103.fs1.hubspotusercontent-na1.net/hubfs/21164103/Threat%20Intelligence%20Content%20Update%20Social.jpg",
    "width" : 900
  },
  "mainEntityOfPage" : "https://www.tidalcyber.com/threat-updates/threat-intel-content-update-6/10/2025",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "Threat Intelligence Content Updates"
  }
}
```