Scattered Spider is a loosely organized, predominantly English-speaking cybercriminal collective known for aggressive social engineering, credential theft, SIM swapping, help-desk impersonation, and data extortion. The group is widely tracked under multiple aliases including UNC3944, Octo Tempest, 0ktapus, Muddled Libra, Roasted 0ktapus, Storm-0875, Star Fraud, Scatter Swine, and Scattered Swine. It is frequently described as part of, or closely associated with, the broader criminal ecosystem known as The Com. Scattered Spider has targeted large enterprises and critical services across the United Kingdom and United States, including telecommunications providers, technology companies, retailers, casinos, airlines, insurers, cloud service providers, healthcare organizations, and public-sector transportation infrastructure. The group has been linked to numerous high-profile intrusions and extortion operations from at least 2022 onward. The actor is especially notable for intrusion methods that focus on people rather than technical exploitation. Common tradecraft includes vishing, impersonating employees to persuade IT help desks to reset passwords or authentication factors, abusing identity recovery and enrollment workflows, using phishing pages that mimic enterprise single sign-on portals, conducting MFA fatigue or challenge relaying, and leveraging SIM swaps to bypass account protections. In some operations, members have impersonated support personnel to convince victims to install remote management tools or authenticate to attacker-controlled infrastructure. Recent overlapping activity tied by researchers to The Com ecosystem has also involved abuse of passkey-enrollment workflows to establish durable account access for later data theft and extortion. After gaining access, Scattered Spider actors commonly move laterally through enterprise environments, seek elevated privileges, access cloud and identity platforms, and exfiltrate sensitive data for extortion. The group has been associated with both ransomware-linked intrusions and data-only extortion, though extortion and operational disruption are more consistently reported than malware deployment itself. Victim impact has included theft of customer and employee data, disruption of business operations, and significant financial losses. Law-enforcement actions in the United Kingdom and United States have identified several alleged or convicted members and associates, including Thalha Jubair, Owen Flowers, Tyler Buchanan, Peter Stokes, and Noah Urban. British authorities described Jubair and Flowers as leading members in connection with the 2024 Transport for London intrusion, a major social-engineering-driven compromise that disrupted numerous internal and customer-facing systems and caused substantial financial damage. Authorities and industry reporting indicate that arrests of key members materially degraded the group’s operational capability, although actors have continued to use the Scattered Spider name in subsequent activity. Scattered Spider is not a nation-state actor. It is a financially motivated cybercrime collective whose operations have caused outsized disruption because of its skill in social engineering, identity compromise, and access abuse against large organizations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
27 malware families attributed to this actor across reporting.
22 additional families tracked in Mallory.
20 CVEs this actor has used in observed campaigns. 20 of them exploited in the wild.
Scattered Spider is known to exploit CVE-2015-2291 which is a vulnerability in the Intel Ethernet diagnostics driver for Windows (iqvw64.sys) that allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges... Scattered Spider exploited CVE-2015-2291 to deploy a malicious kernel driver in the Intel Ethernet diagnostics driver for Windows (iqvw64.sys).
The CVE-2025-61882 campaign is particularly instructive. CrowdStrike assessed with moderate confidence that GRACEFUL SPIDER was involved in mass exploitation of that vulnerability... Exploitation had begun nearly two months earlier on August 9, 2025, well before Oracle's public disclosure.
Additionally, Scattered Spider has exploited CVE-2021-35464 which is a flaw in the ForgeRock AM server. ForgeRock AM server versions before 7.0 have a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages... remote code execution can be triggered by sending a single crafted /ccversion/* request to the server.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
15 more CVEs tied to this actor tracked in Mallory.
232 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named only in passing in connection with extradition news; no operational detail is provided in this article.
Cybercriminal group linked to the 2024 Transport for London intrusion, using vishing/social engineering to obtain account access, steal customer data, and disrupt operations. The group is described by the NCA as heavily degraded following arrests.
A cybercriminal group tied here to the Transport for London attack and broader extortion activity. The content says the group has repeatedly relied on data extortion, SIM-swap attacks, and other social engineering techniques to infiltrate networks and continues to victimize organizations globally.
Cybercrime group tied here to the 2024 Transport for London intrusion that disrupted 148 systems, forced organization-wide password resets, and is described as using social engineering, SIM-swapping, and data extortion. The article also notes repeated use of extortion and social engineering against critical services.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.