Ransomware attacks are surging, and Bitsight data shows just how dramatic the rise has been. Our cyber threat intelligence (CTI) researchers observed a nearly 25% increase in unique ransomware victims listed on leak sites in 2024. Even more striking, the number of ransomware group-operated leak sites grew by 53%, underscoring a broader trend: ransomware has remained the favored tactic of financially motivated cybercriminals, offering a fast, high-impact method to extort substantial payouts from targeted organizations.
One group drawing particular attention is Scattered Spider. Known for its aggressive social engineering techniques and targeting of large enterprises, Scattered Spider has quickly gained notoriety as a capable and persistent threat actor. While not always tied directly to ransomware payloads, the group often acts as an initial access broker, enabling ransomware affiliates to deploy attacks. Recent activity suggests that Scattered Spider remains highly active, adaptive, and aligned with financially driven motives.
Scattered Spider: Who are they?
Scattered Spider (aka 0ktapus, Muddled Libra, Roasted 0ktapus, Scatter Swine, UNC3944, Octo Tempest, Storm-0971, DEV-0971, and Starfraud1) is a highly active and increasingly sophisticated attack group. Operational since at least 2022, Scattered Spider has been observed leveraging ALPHV (BlackCat) ransomware. ALPHV’s website was taken down in a coordinated effort with the FBI in December 2023. It is unclear how active ALPHV is currently. The group is believed to consist primarily of native English-speakers, giving them a linguistic and cultural advantage when conducting social engineering attacks against Western targets. They are thought to be primarily based in the US, UK, and Canada.
Scattered Spider is best known for its use of social engineering, especially phishing and impersonation tactics, to gain initial access. From there, it often leverages vulnerabilities for privilege escalation, enabling deeper compromise within victim networks.
Scattered Spider has been linked to high-profile attacks on major companies such as Caesars Entertainment and MGM Resorts International, underscoring both its capabilities and its focus on high-value targets.
What do they do?
Scattered Spider generally establishes initial access through a combination of phishing and smishing, enabling them to compromise user credentials and intercept multi-factor authentication (MFA) codes. They have been observed launching SIM swapping attacks against users that interact with the smishing/phishing attempts. This initial vector allowed the threat actor to bypass authentication controls and gain unauthorized entry into targeted environments. Once inside an environment, Scattered Spider attempts to escalate privileges and conduct reconnaissance before deploying ransomware.
Scattered Spider leverages techniques such as SIM Swapping and Social Engineering which played a major role in the MGM and Caesar's Palace attacks in September 2023. Scattered Spider demonstrates a deep understanding of enterprise cloud platforms, effectively leveraging misconfigurations and native features within Azure, AWS, and Microsoft 365 to escalate privileges and maintain persistence. From June-December 2022 Scattered Spider heavily targeted Business Process Outsourcing (BPOs) Companies.
Once inside, the group moved quickly to escalate privileges and maintain persistence:
- AWS environment: They exploited compromised credentials to leverage Identity and Access Management (IAM) tokens, granting elevated access and enabling the persistence of control across cloud resources.
- Azure environment: The actors demonstrated advanced familiarity with Azure’s structure, specifically by escalating privileges to gain Tenant Root Group management permissions. This level of access allowed them to control policies, access management, and other critical aspects of the Azure tenant environment.
The group has been observed deploying BlackCat/ALPHV ransomware, leveraging it as a primary tool for financial extortion. Scattered Spider engages in the theft of sensitive data, often threatening public disclosure as leverage—even in the absence of ransomware deployment—marking a dual-threat extortion strategy. Scattered Spider has also been reported to use Living off the Land (LotL) Techniques and Post-Exfiltration File Encryption.
Threat researchers have also observed Scattered Spider operating within the Ransomware-as-a-Service (RaaS) ecosystem. The group has been linked to the deployment of ransomware variants affiliated with RansomHub and Qilin, signaling a strategic shift toward monetizing access and capabilities through partnership with established RaaS operators.