Home/Threat Actor/Scattered Spider
Threat Actor

Scattered Spider

scattered_spider · predominantly_western · active since 2022

Scattered Spider (UNC3944 / Octo Tempest / Muddled Libra / Roasted 0ktapus / 0ktapus / Storm-0875 / Star Fraud / DEV-0537 / G1015) is a financially-motivated organized cyber-criminal cluster active since at least 2022 composed predominantly of English-speaking-native operators from Western jurisdictions (UK, US, Canada), operationally distinctive among publicly- tracked cyber-criminal clusters (which are predominantly Russian-speaking, Eastern European, or Asian) and enabling the cluster's signature voice-phishing tradecraft against English- language IT helpdesks that traditional cyber-criminal defender threat-modeling underweighted prior to 2022-2023, with the strongest formal-attribution profile of any contemporary publicly-tracked cyber-criminal cluster grounded in November 2024 US DOJ Northern District of California indictment of five individuals (Ahmed Elbadawy, Noah Urban / "King Bob", Evans Osiebo, Joel Evans, Tyler Buchanan), July 2024 UK NCA arrest of seventeen-year-old in Walsall England, and AA23-320A FBI+CISA joint cybersecurity advisory (November 16, 2023); most operationally consequential operations the September 2023 near-concurrent attacks on MGM Resorts International (approximately one hundred million US dollar operational impact across ten days of disruption) and Caesars Entertainment (reportedly approximately fifteen million US dollar ransom payment per SEC filings), both as BlackCat / ALPHV ransomware affiliate with the MGM attack reportedly initiated by a ten- minute vishing call to an MGM IT helpdesk.

defined operationally by the signature smishing-to-vishing tradecraft (SMS phishing followed by voice phishing to IT helpdesks for password / MFA / remote-access resets per Mandiant January 2023 UNC3944 disclosure), MFA-bombing, SIM-swapping monetization via compromised mobile-carrier-employee accounts, 0ktapus-style SSO-impersonating phishing kits, predominantly-legitimate remote-access tools (AnyDesk + ScreenConnect + TeamViewer + Splashtop + RustDesk) for hands-on-keyboard operations rather than custom implants, and evolving ransomware partnerships BlackCat / ALPHV - RansomHub - Qilin - Akira - DragonForce across 2023-2025.

predominantly_western confidence: high 28 aliases MITRE ATT&CK G1004 ↗

Profile

Scattered Spider (also tracked as UNC3944, Octo Tempest, Muddled Libra, Roasted 0ktapus, Storm-0875, Star Fraud, DEV-0537, and MITRE ATT&CK G1015) is a financially-motivated organized cyber-criminal cluster active since at least 2022, composed predominantly of English-speaking-native operators from Western jurisdictions including the United Kingdom, United States, Canada, and adjacent English-speaking countries. The English-speaking- native composition is operationally distinctive among publicly- tracked cyber-criminal clusters (which are predominantly Russian- speaking, FIN7, Conti, REvil, BlackCat operators, Eastern European, or Asian) and enables the cluster's signature voice- phishing (vishing) social-engineering tradecraft against English- language IT helpdesks, a capability not readily available to non-English-speaking-native competitors. Members of the cluster are sometimes described in vendor reporting as associated with the broader online subculture sometimes referred to as "The Com" , an English-speaking-native online community originally focused on gaming, SIM-swapping, and social-engineering activity that has produced multiple financially-motivated cyber-criminal clusters. The cluster has the strongest formal-attribution profile of any contemporary publicly-tracked cyber-criminal cluster: November 2024 US DOJ Northern District of California indictment charging five individuals (Ahmed Hossam Eldin Elbadawy, Noah Michael Urban / "King Bob", Evans Onyeaka Osiebo, Joel Martin Evans, and Tyler Robert Buchanan) with multiple counts of conspiracy and wire fraud for Scattered Spider membership.

July 2024 UK National Crime Agency arrest of a seventeen-year-old in Walsall England.

June 2024 arrest of Tyler Buchanan in Spain followed by November 2024 extradition to US.

AA23-320A FBI+CISA cybersecurity advisory (November 16, 2023) representing the highest-tier US-government formal public attribution. The cluster's most operationally consequential and publicly- visible operations were the September 2023 near-concurrent attacks on MGM Resorts International and Caesars Entertainment. The MGM Resorts attack disrupted operations across MGM properties for approximately ten days (slot machines, hotel check-in systems, digital room keys, restaurant POS systems, customer-facing IT services) with MGM disclosing approximately one hundred million US dollars in operational impact. The Caesars Entertainment attack was reportedly resolved via approximately fifteen million US dollar ransom payment per SEC filings. Both attacks involved BlackCat / ALPHV ransomware deployment with Scattered Spider as the affiliate operating the initial-access-through-deployment chain. The September 2023 operations were operationally consequential not only for the affected companies but for broader corporate-security understanding of social-engineering tradecraft sophistication, the MGM attack reportedly began with a ten- minute vishing call to an MGM IT helpdesk to reset credentials for an employee Scattered Spider had identified via LinkedIn. The simplicity of the initial-access contrasted dramatically with the operational impact. The cluster's defining initial-access tradecraft is the smishing- to-vishing combination documented in Mandiant's January 2023 UNC3944 disclosure: SMS phishing (smishing) of target-organization employees with credentials-and-MFA-harvesting phishing pages, followed by voice-phishing (vishing) calls to IT helpdesks impersonating those employees to request password resets, MFA resets, or remote-access tool installation. The smishing-to- vishing pattern combines automated phishing with manual social- engineering execution and represents an operationally sophisticated tradecraft that distinguishes the cluster from predominantly-automated phishing-kit-only competitors. Additional initial-access tradecraft includes MFA-bombing (MFA-fatigue attack, repeatedly issuing MFA push notifications until victim approves out of frustration or confusion), SIM-swapping (signature secondary monetization tradecraft for cryptocurrency and high-value-account theft via compromised mobile-network- operator employee accounts), and 0ktapus-style SSO-impersonating phishing kits. Post-initial-access tradecraft relies predominantly on legitimate remote-access tools (AnyDesk, ScreenConnect, TeamViewer, Splashtop, RustDesk) for hands-on-keyboard operations rather than on custom implants. The "living-off-the-land" tradecraft using legitimate remote-access tools and legitimate cloud services (ngrok tunneling, Cloudflare tunneling, residential- proxy services for source-address obfuscation) reduces detection-surface on traditional endpoint-implant-detection controls and is consistent with broader contemporary cyber- criminal tradecraft trends. The cluster makes substantial use of legitimate Microsoft Azure / AWS / Okta / Salesforce / Slack administrative access following initial-access compromise of cloud-administrative credentials. Ransomware-partnership relationships have evolved across 2023- 2025: BlackCat / ALPHV affiliate during September 2023 MGM and Caesars operations.

transition to RansomHub affiliate in 2024 (following BlackCat's March 2024 exit-scam in which BlackCat operators kept the Change Healthcare ransom payment without sharing affiliate cut)

Qilin partnership in late 2024; additional Akira and DragonForce partnerships across 2024-2025. A handful of operational notes: First, the cluster represents a meaningful operational-pattern shift in the publicly-tracked cyber-criminal cluster ecosystem. Most predecessor cyber-criminal clusters (FIN7, Conti, REvil, LockBit operators) are Eastern European with limited English- speaking-native social-engineering capability. Scattered Spider's English-speaking-native composition enables fundamentally different tradecraft (sophisticated vishing against English- language helpdesks) that traditional cyber-criminal-cluster defender threat-modeling underweighted prior to 2022-2023. Second, the cluster's analytical profile differs from FIN7 (already covered as fin7.yaml) in several ways despite both being financially-motivated organized cyber-criminal clusters: operator composition (English-speaking-native vs Russian- speaking-native), operational tradecraft (smishing-to-vishing and social engineering vs spear-phishing-and-malware-implant deployment), monetization (ransomware-affiliate and SIM-swapping vs POS-data-theft and ransomware-affiliate), and operational personnel structure (fluid "The Com" subculture-based with rolling membership vs corporate-style hierarchical management via front companies). The differences should inform analytical framing. Third, the cluster has demonstrated operational continuity through membership turnover. Younger English-speaking-native operators continue to be recruited into "The Com" online subculture from which Scattered Spider draws personnel, with operations continuing under apparent rolling-membership rather than fixed core operator group. The pattern complicates straightforward law-enforcement disruption, arresting individual operators removes specific personnel but does not necessarily disrupt the broader subculture from which replacement personnel are recruited. Fourth, the cluster represents one of the most operationally consequential financially-motivated clusters of the 2022-2025 period and a critical reference for understanding modern cyber-criminal operations against English-speaking-organization victims. The MGM Resorts and Caesars Entertainment operations collectively contributed to substantially elevated corporate security attention to social-engineering tradecraft and represent a foundational data point in contemporary cyber- criminal-cluster threat modeling.

Aliases

28
scattered spiderscattered_spiderscatteredspiderunc3944unc_3944unc 3944octo tempestocto_tempestoctotempestmuddled libramuddled_libramuddledlibraroasted 0ktapusroasted_0ktapus0ktapusoktapusstorm-0875storm 0875storm_0875star fraudstar_fraudstarfrauddev-0537dev_0537dev0537g1015atk 252atk252

MITRE ATT&CK aliases

2
Additional names MITRE lists for G1004.
LAPSUS$Strawberry Tempest

Notable Campaigns

10
2024-2025Continued Operations Despite Law-Enforcement Pressure (2024-2025)
2024UK National Crime Agency Arrest, 17-Year-Old in Walsall, England (July 18, 2024)
2024US DOJ Northern District of California Indictment, Five Individuals (November 20, 2024)
2023-2025Ransomware Partnership Evolution, BlackCat / ALPHV - RansomHub - Qilin - Akira - DragonForce (2023-2025)
2023Mandiant: UNC3944 Disclosure and Smishing-to-Vishing Tradecraft (January 2023)
2023MGM Resorts International + Caesars Entertainment Ransomware Attacks (September 2023)
2023FBI + CISA AA23-320A Joint Cybersecurity Advisory (November 16, 2023)
2023Microsoft: Octo Tempest Disclosure (October 2023)
2022-2023Telecommunications Sector Compromise and SIM-Swapping Operations (2022-2023)
20220ktapus / Roasted 0ktapus Phishing Campaign (June-August 2022)

Attribution & Reporting

Attributed by
FBI Cyber DivisionCISA (US Cybersecurity and Infrastructure Security Agency)United States Department of JusticeMandiant / Google Cloud Threat IntelligenceMicrosoft Threat Intelligence CenterPalo Alto Networks Unit 42CrowdStrikeTrellixRecorded Future Insikt GroupSentinelOneSophosProofpointGroup-IBCybereasonTrustwave SpiderLabsPRODAFTPWC Threat IntelligenceUK National Crime AgencyCovewareHalcyonGuidePoint Security
Key reporting
reportGroup-IB: 0ktapus Phishing Campaign Disclosure (August 25, 2022), earliest publicly-documented cluster activity
reportMandiant / Google Cloud Threat Intelligence: UNC3944 SMS Phishing SIM Swapping Ransomware (January 2023), seminal smishing-to-vishing tradecraft disclosure
reportMicrosoft Threat Intelligence Center: Octo Tempest Crosses Boundaries to Facilitate Extensive Cross-Domain Ransomware Attacks (October 25, 2023)
reportPalo Alto Networks Unit 42: Muddled Libra Detailed Operational Analysis
reportFBI + CISA: AA23-320A Joint Cybersecurity Advisory, Scattered Spider (November 16, 2023), highest-tier US-government formal public attribution
reportCrowdStrike: Scattered Spider Attempts to Avoid Detection with Bring-Your-Own-Vulnerable-Driver (multiple years)
reportUK National Crime Agency: 17-Year-Old Cyber-Crime Suspect Arrested (July 18, 2024)
reportUS DOJ Northern District of California: Five Defendants Charged with Cybercrimes Related to Scattered Spider Hacking Group (November 20, 2024), comprehensive formal-attribution event
reportTrellix: Scattered Spider Continued Tracking (multiple years)
reportRecorded Future Insikt Group: Scattered Spider Ransomware Affiliate Tracking (multiple years)
reportSekoia: Scattered Spider COM Cybercrime Tracking (2023-2024)
reportCybereason: Scattered Spider Operational Tracking
reportTrustwave SpiderLabs: Scattered Spider Continued Tracking
reportPRODAFT: Scattered Spider Detailed Operational Analysis
reportCoveware: Scattered Spider Ransomware Affiliate Tracking
reportHalcyon: Scattered Spider Operational Profile
reportGuidePoint Security: Scattered Spider Incident Response Tracking
reportMalpedia Actor Profile: Scattered Spider
reportMITRE ATT&CK Group G1015, Scattered Spider

Operational

State sponsor

Scattered Spider is a financially-motivated organized cyber- criminal cluster, not a state-aligned cluster, composed predominantly of English-speaking-native operators from Western jurisdictions including the United Kingdom, United States, Canada, and adjacent English-speaking countries. The cluster's English-speaking-native composition is operationally distinctive among publicly-tracked cyber-criminal clusters, which are predominantly Russian-speaking (FIN7, Conti, REvil, BlackCat / ALPHV operators, etc.), Eastern European, or Asian. The English- speaking-native composition enables the cluster's signature voice-phishing (vishing) social-engineering tradecraft against English-language IT helpdesks, a capability not readily available to Russian-speaking-native or Eastern-European cyber-criminal clusters.

Multiple law-enforcement actions have established specific individual-operator attribution including the July 2024 UK National Crime Agency arrest of a seventeen-year-old in Walsall, England subsequently linked to Scattered Spider operations (subsequent sealed proceedings), the November 2024 arrest of US national Tyler Buchanan in Spain (subsequently extradited to US) charged with Scattered Spider membership and racketeering, and the November 2024 US DOJ Northern District of California indictment of five individuals charged with multiple counts of conspiracy and wire fraud. The cluster has operated as a BlackCat / ALPHV ransomware affiliate, then as a RansomHub ransomware affiliate, then as a Qilin ransomware affiliate, demonstrating operational flexibility in ransomware- partnership relationships. Members of the cluster are sometimes described in vendor reporting as associated with the broader online subculture sometimes referred to as "The Com", an English-speaking-native online community originally focused on gaming, SIM-swapping, and social-engineering activity that has produced multiple financially-motivated cyber-criminal clusters.

Motivations
financial_gain, financially_motivated, cybercrime, extortion, double_extortion, ransomware_deployment, cryptocurrency_theft, data_theft_for_extortion, sim_swapping_for_cryptocurrency_theft, business_email_compromise, reputational_damage_for_extortion_leverage
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)54/60 · 90%
Analytics (MITRE CAR)27/60 · 45%
Runtime / container (Falco)6/60 · 10%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)13/60 · 21%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

3 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MEGA NZ EXFILTRATIONMETERPRETERMFA BOMBINGMFA FATIGUE ATTACKMICROSOFT THEMED PHISHINGMSHTASIM SWAPSIM SWAPPINGSPLASHTOP
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin