Scattered Spider

MITRE ATT&CK: G1015 View on attack.mitre.org

Aliases: Roasted 0ktapus, Octo Tempest, Storm-0875, UNC3944, Muddled Libra, Oktapus, Scattered Swine, Scatter Swine, 0ktapus, Storm-0971, DEV-0971, Starfraud, Scattered Spider, SCATTERED SPIDER

First seen
2022-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
advanced
Resource level
organization
Actor type
criminal
Related IoCs
28 (7 malicious)
Last IoC activity
2026-08-28 16:13:21
Profile updated
2026-07-07 12:33:42

Targeted industries: technology-and-telecommunications retail-and-hospitality manufacturing financial-services

Context

Scattered Spider is a native English-speaking cybercriminal group active since at least 2022. The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. Scattered Spider relies heavily on social engineering, including impersonating IT and help-desk staff, to gain initial access, bypass multi-factor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. Scattered Spider had expanded into hybrid cloud and identity environments, using help-desk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365.

Recent IoC activity

7 malicious indicators in Maltiverse are attributed to Scattered Spider (G1015). The 7 most recently updated:

Detection coverage

  • 27 YARA rules
  • 973 Sigma rules

Malware & tools used

  • Phishing for Information (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Code Signing (attack-pattern)
  • Conditional Access Policies (attack-pattern)
  • Cloud Infrastructure Discovery (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Email Forwarding Rule (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Valid Accounts (attack-pattern)
  • NTDS (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Domain Account (attack-pattern)
  • Trust Modification (attack-pattern)
  • Account Discovery (attack-pattern)
  • Email Hiding Rules (attack-pattern)
  • Social Media Accounts (attack-pattern)
  • Steal Web Session Cookie (attack-pattern)
  • Tool (attack-pattern)
  • Private Keys (attack-pattern)
  • Gather Victim Identity Information (attack-pattern)
  • Cloud Service Dashboard (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • Unix Shell (attack-pattern)
  • External Remote Services (attack-pattern)
  • SSH (attack-pattern)

Reports & references

  • cybersecurity-insiders.com — Scattered Spider Managed Mgm Resort Network Outage Brings 8M Loss Daily (report)
  • loginradius.com — Oktapus Phishing Targets Okta Identity Credentials (report)
  • attackiq.com — Attack Graph Response To Cisa Advisory Aa23 320A (report)
  • Mandiant — Unc3944 Sms Phishing Sim Swapping Ransomware (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)
  • MITRE ATT&CK — G1015 (report)
  • cloud.google.com — Defending Vsphere From Unc3944 (report)
  • cloud.google.com — Unc3944 Proactive Hardening Recommendations (report)
  • CISA — Aa23 320A (report)
  • CrowdStrike — Scattered Spider (report)
  • CrowdStrike — Analysis Of Intrusion Campaign Targeting Telecom And Bpo Companies (report)
  • CrowdStrike — Scattered Spider Attempts To Avoid Detection With Bring Your Own Vulnerable Driver Tactic (report)
  • Microsoft — Octo Tempest Crosses Boundaries To Facilitate Extortion Encryption And Destruction (report)

Attributed from

  • C0027 (campaign)
  • Scattered Spider TTP Evolution - SaaS Targeting (campaign)

External references