Home
Glossary
Scattered Spider
Table of contents
5 min
H2 title on one or more lines.
Share
Updated on
June 22, 2026

Scattered Spider threat actor

Scattered Spider is a financially motivated cybercriminal group, active since at least 2022, that has become one of the most disruptive threat actors targeting Western enterprises. It's best known for social engineering rather than technical exploits: its operators phone corporate IT help desks, impersonate employees, and talk their way past passwords and multi-factor authentication (MFA) to gain access, then escalate to data theft, extortion, and ransomware. Tracked under many names, including UNC3944, Muddled Libra, Octo Tempest, 0ktapus, Scatter Swine, and Star Fraud, the group is a loose, decentralized network of mostly young, native English-speaking members operating from the US, UK, and Europe, loosely part of a broader online community known as The Com. High-profile targets include MGM Resorts, Caesars Entertainment, Twilio, Transport for London, and major UK retailers such as Marks & Spencer.

Key takeaways

  • Identity is the attack surface. Scattered Spider leads with social engineering, not zero-days, and typically arrives already authenticated by abusing help desks and MFA.
  • Many names, one cluster. UNC3944, Muddled Libra, Octo Tempest, 0ktapus, and others are aliases used by different vendors for overlapping activity under a common umbrella.
  • Young, English-speaking, decentralized. Members are reportedly 16 to 22 years old, based in Western countries, and organized as a fluid network rather than a hierarchy.
  • From access broker to ransomware affiliate. The group evolved from credential phishing into deploying ALPHV/BlackCat, DragonForce, and other ransomware, often with double extortion.
  • Built on legitimate tools. It abuses RMM software (AnyDesk, TeamViewer, Splashtop), commercial VPNs, and living-off-the-land techniques to blend into normal IT activity.

Aliases

  • UNC3944
  • Muddled Libra
  • Octo Tempest
  • 0ktapus
  • Roasted 0ktapus
  • Scatter Swine
  • Star Fraud
  • LUCR-3

Who are the members?

Unlike the Eastern European ransomware crews it sometimes partners with, Scattered Spider is composed largely of native English speakers, reportedly aged roughly 16 to 22, operating primarily from the United States, the United Kingdom, and Europe. Fluent, culturally native social engineering is far more convincing to a Western help desk than a scripted call from overseas, and that's a core part of what makes the group effective. The collective has no clear leadership; it's a decentralized network whose members coordinate over platforms like Telegram and Discord and whose affiliations shift over time. Law enforcement made several arrests in 2024, including alleged key figures, and US prosecutors charged multiple members, which slowed operations. The group's decentralized structure has allowed activity to continue, with new developers and techniques observed in 2025.

How Scattered Spider attacks: tactics, techniques, and procedures

Scattered Spider's tradecraft comes down to a simple, powerful idea: it's easier to log in than to hack in. The entry point is almost never a vulnerability. It's a person. A typical intrusion unfolds in stages.

Reconnaissance

Operators map the target using LinkedIn, company websites, and open-source intelligence to identify help desk staff, IT administrators, and executives with elevated access, along with internal jargon and vendor relationships. This happens entirely outside the network and generates no alerts.

Initial access through social engineering

The group's signature moves all target identity:

  • Help desk impersonation: calling IT support posing as an employee, often citing travel or a lockout, and providing personally identifiable information (PII) gathered beforehand to request a password or MFA reset.
  • Vishing and smishing: voice and SMS phishing that impersonate IT staff to harvest credentials and one-time codes.
  • MFA fatigue (push bombing): flooding a user with authentication prompts until they approve one.
  • SIM swapping: hijacking a target's phone number at the carrier level to intercept SMS-based one-time passwords.

Persistence, evasion, and escalation

Once inside, the group installs commercial remote monitoring and management (RMM) tools such as AnyDesk, Splashtop, and TeamViewer precisely because they look like legitimate business software, and uses commercial VPNs to mask location. It relies heavily on living-off-the-land techniques and allowlisted applications, and has even disabled endpoint detection and response (EDR) products from within the vendor's own admin console using access it social-engineered. It demonstrates deep familiarity with cloud platforms, abusing native features and misconfigurations in Azure, AWS, and Microsoft 365 to escalate privileges; in Azure, it has escalated to Tenant Root Group management permissions.

Impact: extortion and ransomware

Operations culminate in mass data theft and, frequently, ransomware. The group practices double extortion, encrypting systems while threatening to leak stolen data, and sometimes extorts on stolen data alone. It has functioned as an initial access broker and as a ransomware affiliate, deploying ALPHV/BlackCat since mid-2023 and later DragonForce, and has been linked to Qilin. It has also been observed pressuring executives directly with data leaks and public shaming to accelerate payment.

Notable attacks

Year Target What happened
2022 Twilio, Cloudflare Large-scale phishing campaign against employees to steal credentials; part of a wave reportedly hitting 130+ organizations.
2023 MGM Resorts A single social-engineering call to the help desk led to BlackCat ransomware on VMware ESXi servers and major operational disruption.
2023 Caesars Entertainment Compromise via social engineering; Caesars reportedly paid a substantial ransom.
2024 Transport for London, Snowflake-related Continued high-profile intrusions; alleged links to the Snowflake customer breaches.
2025 UK retailers (M&S and others) Ransomware attacks using the DragonForce platform, causing significant disruption to major retailers.

Who does Scattered Spider target?

The group is opportunistic but shows clear patterns. It focuses on large enterprise targets, often Fortune 500 companies, across technology, telecommunications, financial services, retail, hospitality and gaming, aerospace, and healthcare. It has a particular appetite for business process outsourcing (BPO) providers and third-party IT and help desk services, because compromising one supplier can open the door to many downstream clients. Targets are concentrated in Western nations, primarily the US and UK, though the group has reached organizations elsewhere. Cloud storage and SaaS providers have become a growing priority, reflecting the group's cloud fluency and its goal of exfiltrating data to attacker-controlled storage.

What makes Scattered Spider different

Most groups phish. Many deploy ransomware. What sets Scattered Spider apart is more specific. Its social engineering operates at a higher level of craft: native English fluency, deep pre-attack research, and a willingness to improvise on a live call make its help desk approaches far more convincing than typical scripted fraud. Its identity-first mindset means it aims to become a legitimate-looking user from the outset, which neutralizes many traditional controls before they can fire. It also broke a longstanding pattern by having English-speaking operators collaborate directly with Eastern European ransomware operations, acting as access broker, affiliate, or both, and it has shown it will burn partners when convenient. When faced with stronger defenses, it shifts tactics, changes ransomware platforms, and evolves its tooling. That adaptability is why any static list of indicators ages quickly. For defenders, signature-based and perimeter-based thinking is the wrong model here. Behavioral, identity-centric detection is what works.

How to defend against Scattered Spider

  1. Harden the help desk. Require strong, non-guessable identity verification for password and MFA resets, such as callbacks to a manager or in-person video verification. The help desk is this group's preferred entry point.
  2. Use phishing-resistant MFA. Move away from SMS and simple push toward FIDO2 or hardware keys, which defeat SIM swapping, MFA fatigue, and real-time phishing kits.
  3. Govern remote access tools. Inventory and restrict RMM software (AnyDesk, TeamViewer, Splashtop), alert on new installs, and block unsanctioned tools.
  4. Watch identity and cloud telemetry. Monitor for impossible travel, unusual help desk resets, new MFA device enrollments, and suspicious Azure, AWS, and Microsoft 365 privilege changes.
  5. Apply least privilege and segmentation. Limit what any single compromised identity can reach, and scrutinize privileged and service accounts.
  6. Rehearse incident response. Maintain immutable, offline backups and a tested plan. This group moves fast from access to encryption.

Expert insight: detecting an adversary that logs in

What makes Scattered Spider genuinely dangerous, and something the Sekoia Threat Detection & Research (TDR) team has documented in depth, is that by the time this group's activity reaches your environment, the attacker is usually already authenticated. Endpoint detection tools are built to catch malicious binaries and known signatures; they're not designed to distinguish a legitimate employee using AnyDesk from an intruder handed those credentials by a tricked help desk agent. A perimeter firewall can't block a VPN session made with valid credentials. Identity has become the real perimeter, and detection has to shift from "is this file malicious?" to "is this behavior normal for this identity?"

That's exactly where a CTI-led security operations center (SOC) platform makes the difference. Sekoia's TDR team tracks Scattered Spider as a cluster spanning its many aliases and continuously monitors its phishing infrastructure, feeding actionable intelligence into Sekoia Intelligence. On the Sekoia SOC platform, detections built from that intelligence target the behaviors this group actually exhibits: anomalous help desk resets and MFA enrollments, impossible travel, suspicious RMM tool activity, and cloud privilege escalation in Azure, AWS, and Microsoft 365. Sekoia Defend includes roughly 1,000 rules mapped to MITRE ATT&CK, and Sekoia has published concrete detection work on emulated Scattered Spider attacks in AWS, catching actions like serial console access and backdoor IAM user creation. Because Scattered Spider targets managed service providers and outsourced help desks so heavily, Sekoia's fit for MSSPs and its European data-sovereignty posture matter to exactly the organizations most in the crosshairs. Paired with automated incident response, a suspicious session can be contained and the account disabled in minutes. Against an adversary that logs in rather than breaks in, correlated identity-and-cloud detection backed by fresh CTI is the defense that works.

Frequently asked questions

Who is Scattered Spider?

Scattered Spider is a financially motivated cybercriminal group active since at least 2022, known for social engineering against Western enterprises. Its operators impersonate employees to trick IT help desks into resetting credentials and MFA, then steal data and deploy ransomware. It's tracked under aliases including UNC3944, Muddled Libra, and Octo Tempest.

What are Scattered Spider's other names?

Common aliases include UNC3944 (Mandiant), Muddled Libra (Unit 42), Octo Tempest (Microsoft, formerly Storm-0875), 0ktapus and Roasted 0ktapus (Group-IB), Scatter Swine (Okta), Star Fraud, and LUCR-3. Vendors use these labels for overlapping activity, though some researchers argue they are related but not identical actors.

What techniques does Scattered Spider use?

Its hallmark is social engineering: help desk impersonation, vishing, smishing, MFA fatigue (push bombing), and SIM swapping to obtain access. After that, it abuses legitimate RMM tools and VPNs, uses living-off-the-land techniques, escalates privileges in cloud environments, and deploys ransomware such as ALPHV/BlackCat and DragonForce, usually alongside data-theft extortion.

What attacks is Scattered Spider known for?

The group is best known for the September 2023 attacks on MGM Resorts and Caesars Entertainment, the 2022 Twilio and Cloudflare phishing campaigns, and 2025 ransomware attacks on UK retailers including Marks & Spencer using DragonForce. It has also been linked to attacks on Transport for London and to the Snowflake customer breaches.

Is Scattered Spider a ransomware group?

It's more accurately a social-engineering-led intrusion set that also deploys ransomware. It began as an initial access broker specializing in phishing, then evolved into a ransomware affiliate, using ALPHV/BlackCat and later DragonForce. It often extorts targeted organizations on stolen data alone, without necessarily deploying ransomware.