Threat Actor Profile

Scattered Spider

Aliases
  • 0ktapus
  • Oktapus
  • UNC3944
  • Octo Tempest
  • Muddled Libra
  • Scatter Swine
  • Storm-0875
Motivation
Cryptocurrency theft, Data theft, Extortion, Financial gain, Ransomware deployment
Cause
Cybercriminal
Recent Activity

Scattered Spider remains a highly active social-engineering-driven cybercriminal threat targeting large enterprises and commercial sectors. CISA and partner agencies have highlighted Scattered Spider activity involving sophisticated helpdesk impersonation, MFA bypass, SIM swapping, data extortion, and ransomware activity. Recent reporting also links Scattered Spider or Scattered Spider-linked clusters to major incidents affecting airlines, retailers, insurers, casino and hospitality organizations, and Jaguar Land Rover.

Primary Targets
  • Large enterprises
  • Telecommunications organizations
  • Business services organizations
  • Technology organizations
  • Transportation organizations
  • Consumer goods organizations
  • Retail organizations
  • Insurance organizations
  • Tourism and hospitality organizations
  • Healthcare organizations
  • Airline organizations
  • Commercial facilities organizations
  • Cryptocurrency organizations
  • Third-party IT providers
Target Locations
  • Australia
  • Canada
  • France
  • Japan
  • Netherlands
  • United Kingdom
  • United States
Target Sectors
  • Business Services
  • Commercial Facilities
  • Consumer Goods
  • Cryptocurrency/Web3
  • Finance
  • Healthcare
  • Insurance
  • Retail
  • Technology
  • Telecommunications
  • Tourism/Hospitality
  • Transportation
Vulnerabilities

Helpdesk social engineering

Phishing

Voice phishing

MFA push bombing

SIM swapping

Credential theft

Weak identity verification procedures

Over-permissioned remote access tools

Exposed remote access services

Third-party IT provider access

Insufficient monitoring of legitimate tunneling and remote management tools

Techniques
  • Social engineering

  • Helpdesk impersonation

  • Phishing

  • Voice phishing

  • SMS phishing

  • MFA bombing

  • SIM swapping

  • Credential theft

  • Account takeover

  • Data theft

  • Data extortion

  • Ransomware deployment

  • Living-off-the-land

  • Remote access tool abuse

  • Tunneling service abuse

  • Legitimate software abuse

  • Identity provider abuse

  • Cloud environment access

  • Lateral movement

  • Privilege escalation

  • Data exfiltration

  • Cryptocurrency theft

Malware Tools
  • Ngrok
  • Tailscale
  • ScreenConnect
  • AnyDesk
  • TeamViewer
  • Splashtop
  • Fleetdeck
  • Level.io
  • Pulseway
  • Tactical.RMM
  • Teleport.sh
  • Mimikatz
  • AveMaria
  • Raccoon Stealer
  • VIDAR Stealer
  • RattyRAT
  • BlackCat/ALPHV
  • Qilin
  • DragonForce
Bitsight Contextualized Intelligence
  • Scattered Spider uses helpdesk impersonation, phishing, vishing, MFA bypass, SIM swapping, remote access tools, data theft, extortion, and ransomware deployment.

Defensive Takeaways
  • Enhance employee awareness of phishing, vishing, MFA bombing, and helpdesk impersonation

  • Use phishing-resistant multifactor authentication

  • Enforce strict identity verification procedures for helpdesk password resets and MFA resets

  • Monitor for SIM swapping indicators and suspicious account recovery activity

  • Detect and restrict unauthorized use of remote access and tunneling tools

  • Monitor for unusual activity involving Ngrok, Tailscale, ScreenConnect, AnyDesk, TeamViewer, Splashtop, and similar tools

  • Harden identity provider policies and monitor for suspicious authentication behavior

  • Limit access to remote desktop services and administrative tools

  • Strengthen third-party IT provider access controls

  • Develop and test incident response plans for data extortion and ransomware scenarios

How Bitsight Helps

Understanding threat actor capabilities is only half the battle—the other half is knowing whether your organization is in their crosshairs. See how Bitsight threat intelligence helps you move from observation to action.

Request threat intel demo