Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Scattered Spider

Also known as: Roasted 0ktapus, Octo Tempest, Storm-0875, UNC3944, Muddled Libra, Oktapus, Scattered Swine, Scatter Swine, 0ktapus, Storm-0971, DEV-0971, Starfraud

Description

Scattered Spider is a native English-speaking cybercriminal group active since at least 2022. (Citation: CrowdStrike Scattered Spider Profile) (Citation: MSTIC Octo Tempest Operations October 2023) The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. (Citation: MSTIC Octo Tempest Operations October 2023) Scattered Spider relies heavily on social engineering, including impersonating IT and help-desk staff, to gain initial access, bypass multi-factor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. (Citation: CISA Scattered Spider Advisory November 2023) (Citation: CrowdStrike Scattered Spider BYOVD January 2023) (Citation: Crowdstrike TELCO BPO Campaign December 2022) Scattered Spider had expanded into hybrid cloud and identity environments, using help-desk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365. (Citation: Mandiant UNC3944 May 2025)

AI Analysis

· 1 week ago

Executive Summary

Scattered Spider is a cybercriminal group known for sophisticated social engineering attacks, targeting various sectors including finance and cloud environments. They employ ransomware and tools like BlackCat to achieve financial gains.

Goals & Targeting

The group targets diverse industries to maximize financial gain and avoid detection. Their focus on cloud environments indicates a strategic shift towards higher-value assets, expanding their geographic reach beyond initial regions for broader impact.

Enhanced Description

Scattered Spider operates since at least 2022, primarily engaging in social engineering and exploiting cloud infrastructure. Initially targeting CRM and BPO firms, they expanded to include gaming, hospitality, and financial sectors. Their tactics involve impersonating IT staff to bypass MFA, using tools like Raccoon Stealer and WarzoneRAT. They have shown adaptability by integrating with attack frameworks like BlackCat and utilizing techniques across various MITRE ATT&CK categories.

Key Capabilities

  • Social engineering via impersonation
  • Bypassing MFA
  • Ransomware deployment
  • Cloud environment exploitation

MITRE ATT&CK Tactics

Initial Access
Execution
Defense Evasion
Credential Access

ATT&CK Techniques

T1490: Inhibit System Recovery
T1685: Disable or Modify Tools
T1018: Remote System Discovery
T1539: Steal Web Session Cookie

Software / Tooling

BlackCat
Raccoon Stealer
WarzoneRAT

Campaigns & Victims

Scattered Spider has demonstrated a persistent campaign pattern, evolving from targeting specific sectors to a broader approach. Their operations include high-profile attacks on CRM providers and MSPs, showcasing their capability to adapt and expand their attack vectors.

IOC Patterns

  • Spear-phishing emails mimicking IT staff
  • Exfiltration over cloud services
  • Malware signatures detected in files

Recommended Actions

  • Implement multi-layered MFA solutions
  • Monitor for known tools like BlackCat and Raccoon Stealer
  • Conduct regular threat hunting exercises focusing on cloud environments

Suggested Tags

Ransomware
Financial-Sector
Cloud-Attack
Social-Engineering

Confidence Assessment

High confidence in their operational tactics and tools, but some uncertainty regarding long-term strategy with limited data on first seen activity.

ATT&CK Techniques

Collection
6 techniques
Command & Control
4 techniques
Credential Access
6 techniques
Defense impairment
6 techniques
Discovery
11 techniques
Impact
3 techniques
Persistence
5 techniques
Reconnaissance
4 techniques
Resource Development
4 techniques
Stealth
6 techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. CISA Scattered Spider Advisory November 2023 — CISA. (2023, November 16). Cybersecurity Advisory: Scattered Spider (AA23-320A). Retrieved March 18, 2024.
  2. CrowdStrike Scattered Spider BYOVD January 2023 — CrowdStrike. (2023, January 10). SCATTERED SPIDER Exploits Windows Security Deficiencies with Bring-Your-Own-Vulnerable-Driver Tactic in Attempt to Bypass Endpoint Security. Retrieved July 5, 2023.
  3. CrowdStrike Scattered Spider Profile — CrowdStrike. (n.d.). Scattered Spider. Retrieved July 5, 2023.
  4. Mandiant VMware vSphere JUL 2025 — Mandiant Incident Response. (2025, July 23). From Help Desk to Hypervisor: Defending Your VMware vSphere Estate from UNC3944. Retrieved October 13, 2025.
  5. Mandiant UNC3944 May 2025 — Mandiant Incident Response. (2025, May 6). Defending Against UNC3944: Cybercrime Hardening Guidance from the Frontlines. Retrieved October 13, 2025.
  6. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  7. MSTIC Octo Tempest Operations October 2023 — Microsoft. (2023, October 25). Octo Tempest crosses boundaries to facilitate extortion, encryption, and destruction. Retrieved March 18, 2024.
  8. Crowdstrike TELCO BPO Campaign December 2022 — Parisi, T. (2022, December 2). Not a SIMulation: CrowdStrike Investigations Reveal Intrusion Campaign Targeting Telco and BPO Companies. Retrieved June 30, 2023.

Intel Summary

64

Techniques

3

Tools

0

Campaigns

0

IOCs

0

Observed Data

14

Tactics

Tags

Ransomware
Financial Targeting
Healthcare Targeting
Supply Chain Attack
Financial-Sector
Cloud-Attack
Social-Engineering

Details

MITRE ID
G1015
Type
Unknown
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--44d37b89-a739-4810-9111-0d2617a8939b
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.