Scattered Spider
MITRE ATT&CK: G1015 View on attack.mitre.org
Aliases: Roasted 0ktapus, Octo Tempest, Storm-0875, UNC3944, Muddled Libra, Oktapus, Scattered Swine, Scatter Swine, 0ktapus, Storm-0971, DEV-0971, Starfraud, Scattered Spider, SCATTERED SPIDER
- First seen
- 2022-01-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- advanced
- Resource level
- organization
- Actor type
- criminal
- Related IoCs
- 28 (7 malicious)
- Last IoC activity
- 2026-08-28 16:13:21
- Profile updated
- 2026-07-07 12:33:42
Targeted industries: technology-and-telecommunications retail-and-hospitality manufacturing financial-services
Context
Scattered Spider is a native English-speaking cybercriminal group active since at least 2022. The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. Scattered Spider relies heavily on social engineering, including impersonating IT and help-desk staff, to gain initial access, bypass multi-factor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. Scattered Spider had expanded into hybrid cloud and identity environments, using help-desk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365.
Recent IoC activity
7 malicious indicators in Maltiverse are attributed to Scattered Spider (G1015). The 7 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| IP address | 45.154.138.39 | 2026-08-28 | 9 |
| file sample | mimikatz.x64.exe | 2026-07-25 | 6 |
| file sample | bfa3cf521eefaaecc5d54028b3c12ea571033d4fe98e94d0031912b55071357b | 2025-10-28 | 1 |
| file sample | da8c1976b9756cfb9afdcb4eaca193f411f96cee65835a87b3efb3423b33810b | 2025-10-26 | 1 |
| file sample | df1f54952d918b1ddabf543ac50c2dafbca7aad2e5681824c0d1a44416da9c1d | 2025-10-24 | 1 |
| file sample | c97641412ba384933dae4d4de377bc57bd0c9cd6d17b52a9a38c7c9a6eadd64c | 2025-10-24 | 1 |
| file sample | f51166cf076d96c47b5c2ba22e65903b21e4d6735e585e1c51f796108a0a54f9 | 2025-10-24 | 1 |
Detection coverage
- 27 YARA rules
- 973 Sigma rules
Malware & tools used
- Phishing for Information (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Code Signing (attack-pattern)
- Conditional Access Policies (attack-pattern)
- Cloud Infrastructure Discovery (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Email Forwarding Rule (attack-pattern)
- Spearphishing Link (attack-pattern)
- Valid Accounts (attack-pattern)
- NTDS (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Domain Account (attack-pattern)
- Trust Modification (attack-pattern)
- Account Discovery (attack-pattern)
- Email Hiding Rules (attack-pattern)
- Social Media Accounts (attack-pattern)
- Steal Web Session Cookie (attack-pattern)
- Tool (attack-pattern)
- Private Keys (attack-pattern)
- Gather Victim Identity Information (attack-pattern)
- Cloud Service Dashboard (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- Unix Shell (attack-pattern)
- External Remote Services (attack-pattern)
- SSH (attack-pattern)
Reports & references
- cybersecurity-insiders.com — Scattered Spider Managed Mgm Resort Network Outage Brings 8M Loss Daily (report)
- loginradius.com — Oktapus Phishing Targets Okta Identity Credentials (report)
- attackiq.com — Attack Graph Response To Cisa Advisory Aa23 320A (report)
- Mandiant — Unc3944 Sms Phishing Sim Swapping Ransomware (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Threat Actor Naming (report)
- MITRE ATT&CK — G1015 (report)
- cloud.google.com — Defending Vsphere From Unc3944 (report)
- cloud.google.com — Unc3944 Proactive Hardening Recommendations (report)
- CISA — Aa23 320A (report)
- CrowdStrike — Scattered Spider (report)
- CrowdStrike — Analysis Of Intrusion Campaign Targeting Telecom And Bpo Companies (report)
- CrowdStrike — Scattered Spider Attempts To Avoid Detection With Bring Your Own Vulnerable Driver Tactic (report)
- Microsoft — Octo Tempest Crosses Boundaries To Facilitate Extortion Encryption And Destruction (report)
Attributed from
- C0027 (campaign)
- Scattered Spider TTP Evolution - SaaS Targeting (campaign)
External references
- mitre-attack — G1015
- Roasted 0ktapus
- UNC3944
- Octo Tempest
- Storm-0875
- CISA Scattered Spider Advisory November 2023
- CrowdStrike Scattered Spider BYOVD January 2023
- CrowdStrike Scattered Spider Profile
- Mandiant VMware vSphere JUL 2025
- Mandiant UNC3944 May 2025
- Microsoft Threat Actor Naming July 2023
- MSTIC Octo Tempest Operations October 2023
- Crowdstrike TELCO BPO Campaign December 2022
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy