Skip to main content
Mallory
Financially Motivated29 malware familiesExploits CVEs in the wild

Scattered Spider

Also known as0ktapusDEV-0971LUCR-3Muddled LibraOcto TempestoktapusRoasted 0ktapusScatter Swinescattered_spiderscattered_swinescatteredspiderstar_fraudStarfraudStorm-0875UNC3944

Scattered Spider is a financially motivated cybercriminal threat actor active since at least May 2022. It is tracked under numerous aliases including UNC3944, Octo Tempest, Muddled Libra, Scatter Swine, 0ktapus/Oktapus, Roasted 0ktapus, StarFraud, DEV-0971, LUCR-3, and STORM-0875. Public reporting in the provided content also describes it as a loosely affiliated, primarily English-speaking group, with some reports characterizing members as young individuals from Western countries. The group is strongly associated with social-engineering-led intrusions, especially help-desk impersonation, voice phishing, SMS phishing, SIM swapping, MFA fatigue, and abuse of IT support processes to obtain credentials and bypass multi-factor authentication. Reporting cited here links Scattered Spider to the 0ktapus campaign and to attacks involving fake Okta login pages, follow-up calls impersonating support staff, and targeting of technology companies, telecommunications providers, and cryptocurrency-linked organizations. The actor has also been reported to coerce victims using personal information and threats of physical harm. After initial access, Scattered Spider is described as reviewing internal documentation and procedures, escalating privileges quickly, establishing persistence through VPN access and remote monitoring and management tools, and moving laterally using tools such as Impacket over WMI. The content states that the group has searched for credential storage documentation on compromised hosts, retrieved browser histories via infostealer malware such as Raccoon Stealer, enumerated remote systems including VMware vCenter infrastructure, and used self-signed and stolen certificates, including certificates originally issued to NVIDIA and Global Software LLC. It has also been reported to exploit stolen Azure credentials, abuse a ForgeRock OpenAM vulnerability, use Bring Your Own Vulnerable Driver techniques, deploy RattyRAT and the bedevil Linux rootkit, and modify mailbox rules to suppress security notifications. Scattered Spider has conducted data theft, extortion, and ransomware operations. The content states that it initially monetized intrusions by selling access, then by mid-2023 expanded into double-extortion campaigns using BlackCat/ALPHV ransomware, including deployment on Windows, Linux, and later VMware ESXi systems. It has used legitimate and commodity services for exfiltration and staging, including Rclone, MEGA/MEGAsync, Dropbox, AWS S3, Backblaze, Gofile, Storj, transfer.sh, Temp.sh, shz.al, and Paste.ee, as well as residential proxy services such as NSOCKS and TrueSocks. Targets mentioned in the content span telecommunications, technology, cryptocurrency-related entities, hospitality, retail, media, entertainment, financial services, insurance, aviation, and SaaS/cloud environments. The actor is publicly linked in the provided material to the 2022 Twilio compromise, targeting of Cloudflare employees, Reddit-related activity, and the 2023 Caesars Entertainment and MGM Resorts intrusions, with reporting noting that access to MGM reportedly came from a short help-desk call. The content also links Scattered Spider to major UK retail incidents affecting Marks & Spencer and reporting around Harrods and Co-op, as well as warnings about campaigns against the airline industry and possible but unconfirmed links to incidents affecting Louis Vuitton/LVMH and Qantas. The provided content also notes analytical overlap or reported associations with ShinyHunters, LAPSUS$, and The Com, including 2025 reporting referring to a merged or overlapping brand called "Scattered LAPSUS$ Hunters." However, the content also indicates that Scattered Spider may be better understood as an umbrella cluster encompassing several related intrusion sets rather than a single tightly bounded group.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Consumer Services

Where they target

Geographies tied to known operations.

  • 🇺🇸 United States
MITRE ATT&CK

Tradecraft

38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

14 of 15 tactics50 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
3 techniques
T1589
Gather Victim Identity Information
T1592
Gather Victim Host Information
T1592.001
Hardware
T1598×2
Phishing for Information
T1598.004×3
Spearphishing Voice
TA0042
Resource Development
1 technique
T1588
Obtain Capabilities
T1588.002
Tool
TA0001
Initial Access
5 techniques
T1078×10
Valid Accounts
T1078.004×2
Cloud Accounts
T1133
External Remote Services
T1195×3
Supply Chain Compromise
T1199
Trusted Relationship
T1566×10
Phishing
T1566.003
Spearphishing via Service
T1566.004×2
Spearphishing Voice
TA0002
Execution
1 technique
T1047
Windows Management Instrumentation
TA0003
Persistence
4 techniques
T1078×10
Valid Accounts
T1078.004×2
Cloud Accounts
T1098
Account Manipulation
T1133
External Remote Services
T1136
Create Account
TA0004
Privilege Escalation
3 techniques
T1068×2
Exploitation for Privilege Escalation
T1078×10
Valid Accounts
T1078.004×2
Cloud Accounts
T1098
Account Manipulation
TA0005
Stealth
2 techniques
T1078×10
Valid Accounts
T1078.004×2
Cloud Accounts
T1497
Virtualization/Sandbox Evasion
T1497.001
System Checks
TA0006
Credential Access
6 techniques
T1003
OS Credential Dumping
T1528
Steal Application Access Token
T1539
Steal Web Session Cookie
T1555
Credentials from Password Stores
T1621×6
Multi-Factor Authentication Request Generation
T1649
Steal or Forge Authentication Certificates
TA0007
Discovery
3 techniques
T1082
System Information Discovery
T1217
Browser Information Discovery
T1497
Virtualization/Sandbox Evasion
T1497.001
System Checks
TA0008
Lateral Movement
2 techniques
T1021×3
Remote Services
T1021.003
Distributed Component Object Model
T1570
Lateral Tool Transfer
TA0009
Collection
2 techniques
T1074
Data Staged
T1114
Email Collection
TA0011
Command and Control
1 technique
T1090
Proxy
T1090.002
External Proxy
TA0010
Exfiltration
3 techniques
T1041×5
Exfiltration Over C2 Channel
T1537×2
Transfer Data to Cloud Account
T1567
Exfiltration Over Web Service
TA0040
Impact
1 technique
T1486×12
Data Encrypted for Impact
WEAPONIZED

Associated vulnerabilities

15 CVEs this actor has used in observed campaigns. 15 of them exploited in the wild.

CVE-2015-2291Kernel privilege escalation in Intel Ethernet diagnostics driver (IQVW32.sys/IQVW64.sys)In the wildEvidence5

Scattered Spider has been linked to exploitation of ... legacy bugs like CVE-2015-2291 in Intel driver software to run code in kernel mode.

CVE-2021-35464Unauthenticated RCE in ForgeRock AM via JATO Java DeserializationIn the wildEvidence3

During C0027, Scattered Spider exploited CVE-2021-35464 in the ForgeRock Open Access Management (OpenAM) application server to gain initial access.

CVE-2025-61882Unauthenticated RCE in Oracle E-Business Suite Concurrent Processing BI Publisher IntegrationIn the wildEvidence3

It has since been determined that hackers likely exploited known EBS vulnerabilities patched in July, likely along with a zero-day flaw tracked as CVE-2025-61882. The hacker groups ShinyHunters and Scattered Spider ... have published a proof-of-concept (PoC) exploit that appears to target CVE-2025-61882 ... according to Oracle, CVE-2025-61882 allows unauthenticated remote code execution. CrowdStrike has found evidence that exploitation of CVE-2025-61882 started on August 9.

CVE-2025-9491Microsoft Windows LNK File UI Misrepresentation Remote Code Execution VulnerabilityIn the wildEvidence2

This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.

CVE-2021-31207Post-auth arbitrary file write in Microsoft Exchange Server (ProxyShell)In the wildEvidence1

This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.

10 more CVEs tied to this actor tracked in Mallory.

IOCS

Observables

68 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping38

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal29

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs15

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables68

Domains, IPs, and hashes tied to this actor, refreshed continuously.