Scattered Spider — Ransomware Profile
Scattered Spider is a native English-speaking cybercriminal group active since at least 2022. The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. Scattered Spider relies heavily on social engineering, including impersonating IT and help-desk staff, to gain initial access, bypass multi-factor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. Scattered Spider had expanded into hybrid cloud and identity environments, using help-desk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365.Also tracked as
Roasted 0ktapus, Octo Tempest, Storm-0875, UNC3944, 0ktapus
Tools & malware
- BlackCat Ransomware
- ConnectWise Remote Access
- LaZagne Credential Harvesting
- Mimikatz Credential Harvesting
- ngrok Tunneling Tool
- Raccoon Stealer Infostealer
- Rclone Exfiltration Tool
- Tor Anonymization Tool
- WarzoneRAT Remote Access Trojan
Recent claimed victims
- MGM Resorts International 2023-09-11
Vendor research
- Group-IB Group-IB
- CrowdStrike Services CrowdStrike
- How Microsoft names threat actors Microsoft
- CrowdStrike. (n.d.). Scattered Spider Crowdstrike
- From Help Desk to Hypervisor: Defending Your VMware vSphere Estate from UNC3944 Mandiant
- Not a SIMulation: CrowdStrike Investigations Reveal Intrusion Campaign Targeting Telco and BPO Companies Crowdstrike
- Defending Against UNC3944: Cybercrime Hardening Guidance from the Frontlines Mandiant
- Cybersecurity Advisory: Scattered Spider (AA23-320A) CISA
- SCATTERED SPIDER Exploits Windows Security Deficiencies with Bring-Your-Own-Vulnerable-Driver Tactic in Attempt to Bypass Endpoint Security Crowdstrike
- Octo Tempest crosses boundaries to facilitate extortion AAAAMicrosoft