Scattered Spider
Scattered Spider is a financially motivated cybercriminal threat actor active since at least May 2022. It is tracked under numerous aliases including UNC3944, Octo Tempest, Muddled Libra, Scatter Swine, 0ktapus/Oktapus, Roasted 0ktapus, StarFraud, DEV-0971, LUCR-3, and STORM-0875. Public reporting in the provided content also describes it as a loosely affiliated, primarily English-speaking group, with some reports characterizing members as young individuals from Western countries. The group is strongly associated with social-engineering-led intrusions, especially help-desk impersonation, voice phishing, SMS phishing, SIM swapping, MFA fatigue, and abuse of IT support processes to obtain credentials and bypass multi-factor authentication. Reporting cited here links Scattered Spider to the 0ktapus campaign and to attacks involving fake Okta login pages, follow-up calls impersonating support staff, and targeting of technology companies, telecommunications providers, and cryptocurrency-linked organizations. The actor has also been reported to coerce victims using personal information and threats of physical harm. After initial access, Scattered Spider is described as reviewing internal documentation and procedures, escalating privileges quickly, establishing persistence through VPN access and remote monitoring and management tools, and moving laterally using tools such as Impacket over WMI. The content states that the group has searched for credential storage documentation on compromised hosts, retrieved browser histories via infostealer malware such as Raccoon Stealer, enumerated remote systems including VMware vCenter infrastructure, and used self-signed and stolen certificates, including certificates originally issued to NVIDIA and Global Software LLC. It has also been reported to exploit stolen Azure credentials, abuse a ForgeRock OpenAM vulnerability, use Bring Your Own Vulnerable Driver techniques, deploy RattyRAT and the bedevil Linux rootkit, and modify mailbox rules to suppress security notifications. Scattered Spider has conducted data theft, extortion, and ransomware operations. The content states that it initially monetized intrusions by selling access, then by mid-2023 expanded into double-extortion campaigns using BlackCat/ALPHV ransomware, including deployment on Windows, Linux, and later VMware ESXi systems. It has used legitimate and commodity services for exfiltration and staging, including Rclone, MEGA/MEGAsync, Dropbox, AWS S3, Backblaze, Gofile, Storj, transfer.sh, Temp.sh, shz.al, and Paste.ee, as well as residential proxy services such as NSOCKS and TrueSocks. Targets mentioned in the content span telecommunications, technology, cryptocurrency-related entities, hospitality, retail, media, entertainment, financial services, insurance, aviation, and SaaS/cloud environments. The actor is publicly linked in the provided material to the 2022 Twilio compromise, targeting of Cloudflare employees, Reddit-related activity, and the 2023 Caesars Entertainment and MGM Resorts intrusions, with reporting noting that access to MGM reportedly came from a short help-desk call. The content also links Scattered Spider to major UK retail incidents affecting Marks & Spencer and reporting around Harrods and Co-op, as well as warnings about campaigns against the airline industry and possible but unconfirmed links to incidents affecting Louis Vuitton/LVMH and Qantas. The provided content also notes analytical overlap or reported associations with ShinyHunters, LAPSUS$, and The Com, including 2025 reporting referring to a merged or overlapping brand called "Scattered LAPSUS$ Hunters." However, the content also indicates that Scattered Spider may be better understood as an umbrella cluster encompassing several related intrusion sets rather than a single tightly bounded group.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Consumer Services
Where they target
Geographies tied to known operations.
- 🇺🇸 United States
Tradecraft
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
29 malware families attributed to this actor across reporting.
24 additional families tracked in Mallory.
Associated vulnerabilities
15 CVEs this actor has used in observed campaigns. 15 of them exploited in the wild.
Scattered Spider has been linked to exploitation of ... legacy bugs like CVE-2015-2291 in Intel driver software to run code in kernel mode.
During C0027, Scattered Spider exploited CVE-2021-35464 in the ForgeRock Open Access Management (OpenAM) application server to gain initial access.
It has since been determined that hackers likely exploited known EBS vulnerabilities patched in July, likely along with a zero-day flaw tracked as CVE-2025-61882. The hacker groups ShinyHunters and Scattered Spider ... have published a proof-of-concept (PoC) exploit that appears to target CVE-2025-61882 ... according to Oracle, CVE-2025-61882 allows unauthenticated remote code execution. CrowdStrike has found evidence that exploitation of CVE-2025-61882 started on August 9.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
10 more CVEs tied to this actor tracked in Mallory.
Observables
68 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Highlighted as a notable English-speaking cybercriminal collective within the increasingly fragmented and diverse cybercrime ecosystem.
Conducted social-engineering-driven intrusions, including high-profile casino compromises, using help-desk calls to gain access.
A Com-linked cybercriminal grouping associated with major costly intrusions, especially against cloud and SaaS platforms used across the US economy and the broader Western world.
Financially motivated threat actor associated with social-engineering-led intrusions and ransomware operations affecting entertainment and hospitality environments.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.