Scattered Spider is a financially motivated cybercrime collective known for aggressive social engineering, identity-centric intrusion tradecraft, SIM swapping, credential theft, and data extortion. The group is widely tracked under multiple aliases including Octo Tempest, UNC3944, 0ktapus, Muddled Libra, Roasted 0ktapus, Storm-0875, Star Fraud, Scatter Swine, and Scattered Swine. It is commonly described as a loosely organized, predominantly English-speaking cluster with ties to the broader criminal ecosystem known as The Com. Scattered Spider is notable for targeting people and identity workflows rather than relying primarily on software exploitation. Its operations frequently involve impersonating employees to corporate help desks, convincing support staff to reset passwords, enroll new devices, or weaken multi-factor authentication protections. Reported techniques associated with the group include vishing, SIM swapping, MFA bypass, fake single sign-on or authentication pages, credential harvesting, session hijacking, and abuse of remote access or administrative tooling after initial access. The group has also been linked to extortion-focused intrusions in which data is stolen from enterprise platforms and used to pressure victims. Victimology has included telecommunications providers, retailers, casinos, cloud and technology companies, healthcare organizations, transportation operators, and aviation-related targets. Scattered Spider has been associated with high-profile disruptive and extortion incidents affecting major enterprises and public services. In the United Kingdom, authorities linked members of the group to the 2024 intrusion against Transport for London, which caused major operational disruption and large-scale password resets. The group has also been repeatedly associated with attacks in North America and other regions, reflecting an international victim set. Scattered Spider is not assessed as a nation-state actor. It is a cybercriminal threat actor focused on financial gain, though its operations can create severe downstream operational consequences for critical and public-facing services. Law-enforcement actions in 2025 and 2026, including prosecutions of alleged senior members in the United Kingdom and the United States, were assessed by authorities and industry researchers as materially degrading the group’s core operational capability. Even so, reporting indicates that actors have continued to use the Scattered Spider name or brand after those arrests, so the label may encompass both core members and imitators or adjacent operators.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
27 malware families attributed to this actor across reporting.
22 additional families tracked in Mallory.
20 CVEs this actor has used in observed campaigns. 20 of them exploited in the wild.
Scattered Spider is known to exploit CVE-2015-2291 which is a vulnerability in the Intel Ethernet diagnostics driver for Windows (iqvw64.sys) that allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges... Scattered Spider exploited CVE-2015-2291 to deploy a malicious kernel driver in the Intel Ethernet diagnostics driver for Windows (iqvw64.sys).
The CVE-2025-61882 campaign is particularly instructive. CrowdStrike assessed with moderate confidence that GRACEFUL SPIDER was involved in mass exploitation of that vulnerability... Exploitation had begun nearly two months earlier on August 9, 2025, well before Oracle's public disclosure.
Additionally, Scattered Spider has exploited CVE-2021-35464 which is a flaw in the ForgeRock AM server. ForgeRock AM server versions before 7.0 have a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages... remote code execution can be triggered by sending a single crafted /ccversion/* request to the server.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
15 more CVEs tied to this actor tracked in Mallory.
232 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as an example of a group known to use SIM swapping as part of identity-focused attacks.
Financially motivated threat group abusing identity and access management processes through employee impersonation to reset credentials or bypass MFA.
Mentioned only in passing in a related-articles teaser about an alleged member being extradited; no campaign details are provided in the main content.
Linked to the September 2024 cyberattack against Transport for London that disrupted services and exposed customer personal and banking data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.