Also known as: Roasted 0ktapus, Octo Tempest, Storm-0875, UNC3944, Muddled Libra, Oktapus, Scattered Swine, Scatter Swine, 0ktapus, Storm-0971, DEV-0971, Starfraud
Scattered Spider is a native English-speaking cybercriminal group active since at least 2022. (Citation: CrowdStrike Scattered Spider Profile) (Citation: MSTIC Octo Tempest Operations October 2023) The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. (Citation: MSTIC Octo Tempest Operations October 2023) Scattered Spider relies heavily on social engineering, including impersonating IT and help-desk staff, to gain initial access, bypass multi-factor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. (Citation: CISA Scattered Spider Advisory November 2023) (Citation: CrowdStrike Scattered Spider BYOVD January 2023) (Citation: Crowdstrike TELCO BPO Campaign December 2022) Scattered Spider had expanded into hybrid cloud and identity environments, using help-desk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365. (Citation: Mandiant UNC3944 May 2025)
Executive Summary
Scattered Spider is a cybercriminal group known for sophisticated social engineering attacks, targeting various sectors including finance and cloud environments. They employ ransomware and tools like BlackCat to achieve financial gains.
Goals & Targeting
The group targets diverse industries to maximize financial gain and avoid detection. Their focus on cloud environments indicates a strategic shift towards higher-value assets, expanding their geographic reach beyond initial regions for broader impact.
Enhanced Description
Scattered Spider operates since at least 2022, primarily engaging in social engineering and exploiting cloud infrastructure. Initially targeting CRM and BPO firms, they expanded to include gaming, hospitality, and financial sectors. Their tactics involve impersonating IT staff to bypass MFA, using tools like Raccoon Stealer and WarzoneRAT. They have shown adaptability by integrating with attack frameworks like BlackCat and utilizing techniques across various MITRE ATT&CK categories.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Scattered Spider has demonstrated a persistent campaign pattern, evolving from targeting specific sectors to a broader approach. Their operations include high-profile attacks on CRM providers and MSPs, showcasing their capability to adapt and expand their attack vectors.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in their operational tactics and tools, but some uncertainty regarding long-term strategy with limited data on first seen activity.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
64
Techniques
3
Tools
0
Campaigns
0
IOCs
0
Observed Data
14
Tactics