FORENSIA

THREAT_ACTOR · G1015

Scattered Spider

Also known as: Scattered Spider, Roasted 0ktapus, Octo Tempest, Storm-0875, UNC3944

Profile

Scattered Spider is a native English-speaking cybercriminal group active since at least 2022. The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. Scattered Spider relies heavily on social engineering, including impersonating IT and help-desk staff, to gain initial access, bypass multi-factor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. Scattered Spider had expanded into hybrid cloud and identity environments, using help-desk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365.

MITRE ATT&CK ↗

Techniques

64 ATT&CK techniques attributed to this actor.

T1003.003 NTDST1006 Direct Volume AccessT1016 System Network Configuration DiscoveryT1018 Remote System DiscoveryT1021.001 Remote Desktop ProtocolT1021.004 SSHT1021.007 Cloud ServicesT1041 Exfiltration Over C2 ChannelT1059.001 PowerShellT1059.004 Unix ShellT1068 Exploitation for Privilege EscalationT1069 Permission Groups DiscoveryT1069.002 Domain GroupsT1070.008 Clear Mailbox DataT1074 Data StagedT1078 Valid AccountsT1078.004 Cloud AccountsT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1087 Account DiscoveryT1087.002 Domain AccountT1090 ProxyT1098 Account ManipulationT1098.003 Additional Cloud RolesT1105 Ingress Tool TransferT1114 Email CollectionT1114.003 Email Forwarding RuleT1133 External Remote ServicesT1136 Create AccountT1204 User ExecutionT1213.003 Code RepositoriesT1213.005 Messaging ApplicationsT1217 Browser Information DiscoveryT1219.002 Remote Desktop SoftwareT1484.002 Trust ModificationT1486 Data Encrypted for ImpactT1490 Inhibit System RecoveryT1530 Data from Cloud StorageT1538 Cloud Service DashboardT1539 Steal Web Session CookieT1543.002 Systemd ServiceT1552.001 Credentials In FilesT1552.004 Private KeysT1553.002 Code SigningT1555.005 Password ManagersT1556.006 Multi-Factor AuthenticationT1556.009 Conditional Access PoliciesT1564.008 Email Hiding RulesT1567.002 Exfiltration to Cloud StorageT1572 Protocol TunnelingT1578.002 Create Cloud InstanceT1580 Cloud Infrastructure DiscoveryT1583.001 DomainsT1585.001 Social Media AccountsT1588.001 MalwareT1588.002 ToolT1589 Gather Victim Identity InformationT1598 Phishing for InformationT1598.003 Spearphishing LinkT1598.004 Spearphishing VoiceT1621 Multi-Factor Authentication Request GenerationT1657 Financial TheftT1684.001 ImpersonationT1685 Disable or Modify Tools

Software

9 malware/tools attributed to this actor.

MimikatzTorLaZagnengrokConnectWiseWarzoneRATRcloneBlackCatRaccoon Stealer

Related corpus activity

10,045 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Scattered Spider.

IndicatorTypeFamilySevSrc
cve-2023-44976cveransomware852
cve-2026-1969cve851
cve-2025-68670cve852
cve-2026-3102cve853
cve-2025-34117cve851
cve-2021-29441cve851
cve-2026-22584cve852
cve-2025-11837cve852
cve-2025-34054cve854
cve-2014-2321cve851
cve-2020-17456cve851
cve-2025-2492cve852
cve-2013-7471cve851
cve-2021-25646cve851
cve-2025-66478cve852
cve-2025-0921cve852
cve-2021-27076cve851
cve-2013-3307cve852
cve-2016-5681cve852
cve-2016-15047cve854
cve-2024-1781cve851
cve-2018-8007cve851
cve-2022-47945cve851
cve-2021-4045cve851
cve-2020-22653cve852
cve-2020-22658cve852
cve-2026-4368cveransomware851
cve-2017-18377cve851
cve-2025-23304cve852
cve-2026-0740cve851

Showing the top 30 by severity of 10,045.