Scattered Spider — Ransomware Profile

Scattered Spider is a financially motivated, native English-speaking cybercriminal collective active since at least 2022, tracked by Microsoft as Octo Tempest, by Mandiant as UNC3944 and by Palo Alto Unit 42 as Muddled Libra. It gains access almost entirely through social engineering - help-desk impersonation, MFA fatigue, SIM swapping and adversary-in-the-middle phishing - against CRM, BPO, telecom, gaming, hospitality, retail and financial targets, then monetises intrusions through data-theft extortion. It has never operated its own ransomware brand: Microsoft records it becoming an ALPHV/BlackCat affiliate in mid-2023, Mandiant observed no ransomware deployment by the group after early 2024 as it shifted to extortion without encryption, and the spring-2025 UK retail intrusions were paired with DragonForce ransomware. Researchers disagree on whether the name denotes a single crew or an umbrella, with Group-IB describing loosely connected cells inside the wider 'The Com' community rather than one gang; members convicted or charged in the United States and United Kingdom have been US and UK nationals, so no single country of origin is asserted.

Also tracked as

Roasted 0ktapus, Octo Tempest, Storm-0875, UNC3944, 0ktapus, Starfraud, Scatter Swine, LUCR-3

IntelFusions coverage (8)

Tools & malware

Recent claimed victims

Vendor research

Countries linked to this actor

Read the full analysis on IntelFusions