Threat actor
Scattered Spider
Last fetched
Scattered Spider is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 64 techniques and also known as 12 other names.
Also known as
Roasted 0ktapus, Octo Tempest, Storm-0875, UNC3944, Muddled Libra, Oktapus, Scattered Swine, Scatter Swine, 0ktapus, Storm-0971, DEV-0971, Starfraud
Description
[Scattered Spider](https://attack.mitre.org/groups/G1015) is a native English-speaking cybercriminal group active since at least 2022. (Citation: CrowdStrike Scattered Spider Profile) (Citation: MSTIC Octo Tempest Operations October 2023) The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. (Citation: MSTIC Octo Tempest Operations October 2023) [Scattered Spider](https://attack.mitre.org/groups/G1015) relies heavily on social engineering, including impersonating IT and help-desk staff, to gain initial access, bypass multi-factor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. (Citation: CISA Scattered Spider Advisory November 2023) (Citation: CrowdStrike Scattered Spider BYOVD January 2023) (Citation: Crowdstrike TELCO BPO Campaign December 2022) [Scattered Spider](https://attack.mitre.org/groups/G1015) had expanded into hybrid cloud and identity environments, using help-desk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365. (Citation: Mandiant UNC3944 May 2025)
Techniques by tactic
Discovery
- T1016 · System Network Configuration Discovery
- T1018 · Remote System Discovery
- T1069 · Permission Groups Discovery
- T1069.002 · Domain Groups
- T1082 · System Information Discovery
- T1083 · File and Directory Discovery
- T1087 · Account Discovery
- T1087.002 · Domain Account
- T1217 · Browser Information Discovery
- T1538 · Cloud Service Dashboard
- T1580 · Cloud Infrastructure Discovery
Attributed infrastructure
Infrastructure with a published ATTRIBUTED_TO link to Scattered Spider in WhisperGraph. Attribution is sparse graph-wide — this list is rarely exhaustive.
- hessattorneys.co.zaHOSTNAME
References
- https://attack.mitre.org/groups/G1015
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a
- https://www.crowdstrike.com/blog/scattered-spider-attempts-to-avoid-detection-with-bring-your-own-vulnerable-driver-tactic/
- https://www.crowdstrike.com/adversaries/scattered-spider/
- https://cloud.google.com/blog/topics/threat-intelligence/defending-vsphere-from-unc3944
- https://cloud.google.com/blog/topics/threat-intelligence/unc3944-proactive-hardening-recommendations
- https://learn.microsoft.com/en-us/microsoft-365/security/intelligence/microsoft-threat-actor-naming?view=o365-worldwide
- https://www.microsoft.com/en-us/security/blog/2023/10/25/octo-tempest-crosses-boundaries-to-facilitate-extortion-encryption-and-destruction/
- https://www.crowdstrike.com/blog/analysis-of-intrusion-campaign-targeting-telecom-and-bpo-companies/
- https://www.cybersecurity-insiders.com/scattered-spider-managed-mgm-resort-network-outage-brings-8m-loss-daily/
- https://www.loginradius.com/blog/identity/oktapus-phishing-targets-okta-identity-credentials/
- https://www.attackiq.com/2023/11/21/attack-graph-response-to-cisa-advisory-aa23-320a/
- https://www.mandiant.com/resources/blog/unc3944-sms-phishing-sim-swapping-ransomware
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from Scattered Spider into its techniques, tactics and any attributed infrastructure.
Queries
Resolves the slug to this actor, merging every duplicate node sharing the same name.
MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
a.references AS references, a.campaigns AS campaigns
LIMIT 25Run yourself →Techniques this actor uses, grouped by the tactic each one serves.
MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000Run yourself →Infrastructure publicly attributed to this actor.
MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.