0ktapus is a commercial phishing kit used in social engineering attacks. It provides pre-made templates for realistic fake authentication portals designed to harvest credentials and multi-factor authentication (MFA) codes, and it includes a built-in command-and-control channel via Telegram. Reporting cited in the content links 0ktapus to activity resembling the Muddled Libra cluster, which has overlap with Scattered Spider/Scatter Swine tradecraft, although Unit 42 noted that use of the 0ktapus kit alone is not sufficient for attribution. The kit was referenced in attacks against Okta customers in which threat actors socially engineered IT service desk personnel to reset MFA factors for highly privileged users, enabling takeover of Okta Super Administrator accounts. After gaining elevated access, attackers were reported to impersonate users, assign higher privileges to other accounts, reset enrolled authenticators, remove second-factor requirements from authentication policies, and in some cases configure a second identity provider as an impersonation app using inbound federation (Org2Org) to single sign-on into applications as targeted users. The content states that multiple threat actors have added 0ktapus to their arsenals. Targeting described in the content includes Okta environments and organizations affected through service desk-focused social engineering; related reporting also notes observed targeting by overlapping clusters against telecommunications, BPO, and more recently other sectors including critical infrastructure. No specific IOCs are provided in the content beyond the Telegram-based C2 channel.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Central to the attacks is a commercial phishing kit called 0ktapus, which offers pre-made templates to create realistic fake authentication portals and ultimately harvest credentials and multi-factor authentication (MFA) codes. It also incorporates a built-in command-and-control (C2) channel via Telegram.
1 distinct technique documented for this family, organized by ATT&CK tactic.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial phishing kit used to create fake authentication portals to harvest credentials and MFA codes; includes a built-in C2 channel via Telegram.
0ktapus is a malware toolset associated with the Muddled Libra threat group, known for credential theft and social engineering attacks. It is used to facilitate account compromise and lateral movement within targeted organizations.
0ktapus is a malware toolset associated with the Muddled Libra threat group, known for credential theft and social engineering attacks. It is used to facilitate account compromise and lateral movement within targeted organizations.
0ktapus is a malware toolset associated with the Muddled Libra threat group, known for credential theft and social engineering attacks. It is used to facilitate account compromise and lateral movement within targeted organizations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.