Scattered Spider is a financially motivated cybercriminal threat actor known for account takeover, social engineering, and hands-on intrusion activity against enterprise environments. The group is widely associated with cloud and identity abuse, including theft and misuse of valid credentials and browser or application session material to gain unauthorized access to corporate resources. It has been linked in reporting and detection content with AWS IAM account takeover scenarios and concurrent-session anomalies consistent with session hijacking. The actor has also been associated with Windows defense evasion behavior that weakens Microsoft Defender and related endpoint protections through registry-based configuration changes mapped to ATT&CK T1562.001, Impair Defenses. Observed behaviors include disabling or weakening security controls such as network protection, phishing protection, firewall-related protections, application guard, controlled folder access, reporting, and other Defender monitoring functions. Scattered Spider is commonly discussed alongside aliases and overlaps involving UNC3944, Octo Tempest, Muddled Libra, and references connecting it with Lapsus$-linked or adjacent activity, although those relationships are not always used consistently across vendors. High-confidence evidence in the available material supports identity-focused intrusion activity, session hijacking, credential abuse, and defense evasion on Windows systems.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as part of an analytic story related to AWS IAM account takeover and compromised user accounts; the content does not provide specific operational details about the group itself.
Associated in the content with Windows Defender impairment and registry-based defense evasion activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.