Scattered Spider — Ransomware Profile
Scattered Spider is a financially motivated, native English-speaking cybercriminal collective active since at least 2022, tracked by Microsoft as Octo Tempest, by Mandiant as UNC3944 and by Palo Alto Unit 42 as Muddled Libra. It gains access almost entirely through social engineering - help-desk impersonation, MFA fatigue, SIM swapping and adversary-in-the-middle phishing - against CRM, BPO, telecom, gaming, hospitality, retail and financial targets, then monetises intrusions through data-theft extortion. It has never operated its own ransomware brand: Microsoft records it becoming an ALPHV/BlackCat affiliate in mid-2023, Mandiant observed no ransomware deployment by the group after early 2024 as it shifted to extortion without encryption, and the spring-2025 UK retail intrusions were paired with DragonForce ransomware. Researchers disagree on whether the name denotes a single crew or an umbrella, with Group-IB describing loosely connected cells inside the wider 'The Com' community rather than one gang; members convicted or charged in the United States and United Kingdom have been US and UK nationals, so no single country of origin is asserted.Also tracked as
Roasted 0ktapus, Octo Tempest, Storm-0875, UNC3944, 0ktapus, Starfraud, Scatter Swine, LUCR-3
IntelFusions coverage (8)
- Ransomware crews can hide their tracks in ESX logs 2026-08-07 · Ransomware
- Critical VMware bugs let attackers take over virtual server fleets 2026-07-30 · Vulnerabilities
- DragonForce ransomware posts more than 20 victims in three days 2026-07-17 · Ransomware
- Access broker exploits Citrix bug to plant DragonForce ransomware 2026-07-10 · Ransomware
- Scattered Spider is not one gang but a sprawling cybercrime movement 2026-07-07 · Ransomware
- Scattered Spider (UNC3944) 2025: Teleport as Novel C2 Persistence on AWS EC2, STONESTOP/POORTRY BYOVD EDR Termination, and DragonForce Ransomware Partnerships 2026-02-16 · Cyber Incidents
- Scattered Spider Q2 2025: vCenter Unmanaged VM ntds.dit Dumping, Chisel/Teleport/Pinggy Tunneling, S3 Browser Exfiltration, and Email Transport Rule Hijacking 2026-02-16 · Cyber Incidents
- Inside BlackCat's Kill Chain: Picus Dissects ALPHV Ransomware TTPs After Change Healthcare Mega-Breach 2026-02-16 · Ransomware
Tools & malware
- BlackCat Ransomware
- ConnectWise Remote Access
- Fleetdeck.io tool
- LaZagne Credential Harvesting
- Level.io tool
- Mimikatz Credential Harvesting
- ngrok Tunneling Tool
- Pulseway tool
- Raccoon Stealer Infostealer
- Rclone Exfiltration Tool
- Splashtop tool
- Tactical.RMM tool
- Tailscale tool
- TeamViewer tool
- Tor Anonymization Tool
- VIDAR Stealer malware
- WarzoneRAT Remote Access Trojan
Recent claimed victims
- MGM Resorts International 2023-09-11
Vendor research
- Group-IB Group-IB
- CrowdStrike Services CrowdStrike
- How Microsoft names threat actors Microsoft
- CrowdStrike. (n.d.). Scattered Spider Crowdstrike
- From Help Desk to Hypervisor: Defending Your VMware vSphere Estate from UNC3944 Mandiant
- Not a SIMulation: CrowdStrike Investigations Reveal Intrusion Campaign Targeting Telco and BPO Companies Crowdstrike
- Defending Against UNC3944: Cybercrime Hardening Guidance from the Frontlines Mandiant
- Cybersecurity Advisory: Scattered Spider (AA23-320A) CISA
- SCATTERED SPIDER Exploits Windows Security Deficiencies with Bring-Your-Own-Vulnerable-Driver Tactic in Attempt to Bypass Endpoint Security Crowdstrike
- Octo Tempest crosses boundaries to facilitate extortion AAAAMicrosoft
Countries linked to this actor
- United Kingdom targets
- United States targets