Scattered Spider is a financially motivated cybercrime intrusion set known for aggressive social engineering and high-impact compromises of large enterprises, particularly in the retail sector. The actor is also tracked as KTA243 and UNC3944, and has been associated in reporting with the name Oktapus. The group has been described as primarily English-speaking and operating from the United States and the United Kingdom. Scattered Spider is notable for convincing help-desk and IT personnel to reset passwords or otherwise grant access, as well as for phishing-based intrusion activity. Its operations frequently rely on human-focused initial access rather than novel exploitation, and observed tradecraft includes deceptive social engineering, abuse of legitimate administrative and system-management tools, and post-compromise actions consistent with disruptive enterprise intrusions. Public reporting has linked the group’s tradecraft to attacks against high-profile organizations including major retailers and casino operators. Recent activity has included a shift from prominent United Kingdom retail incidents to targeting retail organizations in the United States. Reporting has described successful compromises in the U.S. retail sector using voice-based social engineering against help desks. Scattered Spider-style activity has also been observed in incidents affecting major U.K. retailers, although some of those intrusions have not been formally attributed with high confidence. Separate reporting has noted overlap or possible interaction with DragonForce ransomware operations, but the exact relationship remains unclear and should not be treated as established fact. The actor’s behavior is consistent with credential theft, initial access through social engineering, persistence and post-exploitation within enterprise environments, and data theft in some incidents. Law-enforcement actions have targeted alleged members, but security researchers assess that the tradecraft continues to be reused and adapted.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Launching a data leak and ransom extortion site targeting Salesforce customers.
Kroll-tracked cluster aligned to Scattered Spider activity patterns; discussed in the context of retail-sector intrusions leveraging social engineering and help-desk targeting.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.