---
title: "Threat Intel Content Update: 7/1/2025"
description: Tidal Cyber's threat intelligence content updates for the week of 7/1/2025- Scattered Spider, North Korean Fraudulent Remote Work Schemes, Wagemole
---

[Threat Intelligence Content Updates ](https://www.tidalcyber.com/threat-updates)

# [Threat Intel Content Update: 7/1/2025](https://www.tidalcyber.com/threat-updates/threat-intel-content-update-7/1/2025)

 Written by [Tidal Cyber](https://www.tidalcyber.com/threat-updates/author/tidal-cyber) | Jul 1, 2025 1:56:54 PM

#### Scattered Spider, North Korean Fraudulent Remote Work Schemes, Wagemole

**Threat Content Highlights**

- The FBI [announced](https://x.com/FBI/status/1938746767031574565) that it recently observed the **Scattered Spider** financially motivated group “expanding its targeting” to the airline sector. 
    - Security researchers [indicate](https://www.linkedin.com/posts/charlescarmakal_scatteredspider-unc3944-socialengineering-activity-7344421800702844931-pBt9) that the group is known to target particular sectors “for a few weeks at a time” before shifting to others.
    - We have extended the [ATT&CK Group object](https://app.tidalcyber.com/groups/3d77fb6c-cfb4-5563-b0be-7aa1ad535337?tab=2) with numerous Technique, Software, and Campaign relationships, and we updated our “Scattered Spider Ecosystem” Threat Profile in early June to reflect the group’s latest reported behaviors.

- The U.S. Department of Justice [announced](https://www.justice.gov/opa/pr/justice-department-announces-coordinated-nationwide-actions-combat-north-korean-remote) arrests and seizures targeting North Korean workers suspected of fraudulently gaining employment with U.S. companies as remote IT workers, in order to generate illicit revenue for their country’s regime. 
    - The actions are positive news, but they also underscore the concerning scale of recent North Korean fraudulent remote work schemes.
    - The [Wagemole Campaign object](https://app.tidalcyber.com/campaigns/92f2bb7e-e08b-476e-a3a2-f94ff1182e72) in the Tidal Cyber knowledge base includes Techniques linked to these types of schemes, including in-depth reconnaissance activity and AI-supported impersonation attempts.

 

[View full post](https://www.tidalcyber.com/threat-updates/threat-intel-content-update-7/1/2025)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Tidal Cyber"
  },
  "dateModified" : "2025-07-01T13:56:54.248Z",
  "datePublished" : "2025-07-01T13:56:54Z",
  "headline" : "Threat Intel Content Update: 7/1/2025",
  "image" : {
    "@type" : "ImageObject",
    "height" : 500,
    "url" : "https://21164103.fs1.hubspotusercontent-na1.net/hubfs/21164103/Threat%20Intelligence%20Content%20Update%20Social.jpg",
    "width" : 900
  },
  "mainEntityOfPage" : "https://www.tidalcyber.com/threat-updates/threat-intel-content-update-7/1/2025",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "Threat Intelligence Content Updates"
  }
}
```