Scattered Spider (UNC3944, Octo Tempest, Muddled Libra, Star Fraud) — Adversary Emulation Profile
Scattered Spider (MITRE ATT&CK G1015) is a financially motivated, predominantly native English-speaking cybercriminal collective active since at least 2022 and widely linked to the loosely affiliated "The Com" social network. The group is exceptional not for novel malware but for aggressive, high-tempo social engineering of human identity processes: it phones and SMS-phishes help desks and employees, impersonates IT staff, bypasses MFA (push bombing, SIM swapping, attacker-registered tokens), and rapidly pivots into cloud identity (Microsoft Entra ID, Okta, AWS, Azure) and virtualization (VMware ESXi/vCenter) before staging data theft and ransomware. It began with the 2022 "0ktapus" Okta-credential phishing wave, escalated to the high-profile 2023 MGM Resorts and Caesars Entertainment intrusions, and through 2024–2025 operated as an affiliate of multiple ransomware-as-a-service brands (BlackCat/ALPHV, RansomHub, Qilin, DragonForce), hitting retail, insurance, and aviation. This profile teaches Decepticon to emulate G1015's signature identity-centric TTPs inside an authorized engagement and helps the blue cell anticipate detection.
Attribution & motivation
- Sponsor / nation: Non-state, criminal. Members are assessed to be primarily young, native English speakers based in the US and UK, affiliated with the broader "The Com" cybercrime community. Not a nation-state actor; multiple arrests and a 2025 US extradition have been reported (per Krebs on Security / Infosecurity Magazine).
- Motivation: Primarily financial — credential theft, SIM-swap fraud / crypto theft, data extortion, and ransomware (
T1657Financial Theft). There is no credible espionage, destructive-only, or influence mandate; destruction (encryption) is in service of extortion. - Confidence: High confidence the cluster tracked as Scattered Spider = UNC3944 (Mandiant/Google) = Octo Tempest / Storm-0875 (Microsoft) = Muddled Libra (Palo Alto Unit 42) = Roasted 0ktapus = Scatter Swine = Star Fraud. Note these vendor clusters overlap but are not byte-for-byte identical; treat as a fluid affiliate community rather than a fixed roster.
Targeting
- Sectors: Initially telecom, BPO/outsourcing, and CRM/SaaS providers (for SIM-swap and downstream access); from 2023 expanded to hospitality & gaming (casinos), retail, technology/MSP, manufacturing, and financial services / insurance; in mid-2025, aviation.
- Regions: Primarily English-speaking targets — United States, United Kingdom, Canada, Australia — with reporting of expansion toward Singapore and India.
- Victim profile: Large enterprises with large outsourced or tiered IT help desks, heavy reliance on SSO/MFA (Okta, Microsoft Entra ID), significant cloud/SaaS footprint, and VMware-virtualized data centers. The human help desk and identity-recovery workflow is the deliberately chosen weak point.
Notable campaigns
- Aug 2022 — "0ktapus" / Roasted 0ktapus: SMS smishing campaign harvesting Okta credentials and OTPs via ~169 lookalike domains; ~130 organizations compromised, including downstream intrusions at Twilio, Cloudflare (blocked), Mailchimp, DoorDash, and LastPass. (Group-IB, "Roasting 0ktapus.")
- Sep 2023 — MGM Resorts & Caesars Entertainment: Help-desk vishing (an employee impersonation reportedly seeded from LinkedIn) granted access; MGM suffered major operational disruption, Caesars reportedly paid a ransom. BlackCat/ALPHV ransomware was associated. (Reuters/CyberScoop reporting; CISA AA23-320A.)
- Nov 16, 2023 — CISA/FBI Joint Advisory AA23-320A first published, codifying the group's TTPs. (CISA.)
- 2024 — RaaS affiliate shift: Following ALPHV's collapse, the group operated with RansomHub and Qilin affiliates.
- Apr–May 2025 — UK retail wave: Marks & Spencer (initial access reportedly Feb 2025), Co-op, and Harrods; M&S disruption estimated in the hundreds of millions of GBP, with DragonForce ransomware deployed against ESXi. UK arrests of four suspects followed. (The Hacker News; Mandiant/Google.)
- Jun 2025 — US insurance sector: Reported intrusions including Philadelphia Insurance Companies and Erie Insurance. (Push Security; Claranet.)
- Late Jun–Jul 2025 — Aviation: FBI warned of expansion to airlines; incidents reported at Hawaiian Airlines, WestJet, and Qantas (third-party contact-center platform). (CSO Online.)
- Jul 29, 2025 — AA23-320A updated by FBI/CISA + international partners (RCMP, ASD's ACSC, AFP, CCCS, NCSC-UK) with TTPs current to June 2025 and confirmation of DragonForce deployment. (IC3/CISA.)
TTPs by ATT&CK tactic
Resource Development
T1583.001Acquire Infrastructure: Domains — registers lookalike/SSO-spoofing domains (e.g.victim-helpdesk[.]com,victim-sso[.]com).T1585.001Establish Accounts: Social Media — builds fake personas; uses LinkedIn for target profiling.T1588.001/T1588.002Obtain Capabilities (Malware/Tools) — acquires info-stealers, RATs, ransomware, and offensive tools (RustScan, LinPEAS, aws_consoler, rsocx, Level RMM).T1102Web Service — stages/downloads tooling from file.io, GitHub, paste.ee.
Initial Access
T1598.004/T1566.004Spearphishing Voice (vishing) — calls help desks/employees impersonating IT to trigger password and MFA resets; signature technique.T1660/T1598.003Phishing (mobile / spearphishing link) — SMS smishing to credential-harvesting portals mimicking SSO.T1598.001Spearphishing Service — Telegram/Teams messages impersonating IT personnel.T1451SIM-Card Swap — social-engineers carriers to port victim numbers and intercept SMS OTPs.T1190Exploit Public-Facing Application — opportunistic (e.g., CVE-2021-35464 in ForgeRock OpenAM).T1133External Remote Services — abuses VPNs, Citrix, and remote-access tooling for entry.T1078/T1078.004Valid Accounts (incl. Cloud) — logs in with socially-engineered credentials; compromised Entra ID/Azure accounts.T1199Trusted Relationship — pivots through MSPs, BPOs, and third-party contact-center platforms.T1621MFA Request Generation — push-bombing / MFA-fatigue until a victim approves.
Execution
T1204User Execution — directs impersonated victims to install RMM agents.T1219.002Remote Desktop Software — deploys TeamViewer, AnyDesk, LogMeIn, ConnectWise, ngrok-based access.T1059.001PowerShell — e.g.,Get-ADUserand recon scripting.T1059.004Unix Shell — installs Teleport and tooling on Linux/ESXi.T1047Windows Management Instrumentation — via Impacket for remote execution/lateral movement.
Persistence
T1098.005Device Registration — registers attacker MFA devices/endpoints for durable access through VPN.T1136Create Account — creates new identities in the victim tenant/domain.T1098/T1098.001/T1098.003Account Manipulation — adds accounts to privileged groups (e.g., ESX Admins), adds cloud credentials, assigns admin roles.T1556.006Modify Authentication Process: MFA — registers own MFA tokens post-compromise.T1484.002Domain Trust Modification — adds a rogue federated IdP to the SSO tenant for backdoor authentication.T1543.002/T1547.005Systemd Service / SSP — Teleport persistence on Linux; Mimikatz SSP.
Privilege Escalation
T1556.009Conditional Access Policies — adds trusted locations / weakens CA to bypass MFA for controlled accounts.T1068Exploitation for Privilege Escalation — has deployed a malicious kernel driver (BYOVD via CVE-2015-2291).T1548.002Bypass UAC — via tooling (BlackCat, WarzoneRAT).
Defense Evasion
T1685Disable or Modify Tools /T1562Impair Defenses — uninstalls/disables EDR and security agents.T1564.008Email Hiding Rules /T1070.008Clear Mailbox Data — auto-deletes vendor security alert emails; deletes traces of its own account activity.T1553.002Code Signing — abuses self-signed and stolen certificates (e.g., NVIDIA, Global Software LLC).T1027Obfuscated Files /T1134Access Token Manipulation — malware-delivered obfuscation and token abuse.
Credential Access
T1003/T1003.003/T1003.006OS Credential Dumping (Mimikatz, LaZagne), NTDS extraction via shadow copies, and DCSync.T1555.005Password Managers — hunts HashiCorp Vault and PAM solutions.T1539Steal Web Session Cookie /T1217Browser Information — harvests cookies and browser data (Raccoon Stealer).T1552.001/T1552.004Credentials in Files / Private Keys — searches credential docs; exfiltrates code-signing certs.T1684.001Impersonation — impersonates IT help desk to reset passwords/MFA.T1589/T1589.001Gather Victim Identity Info / Credentials — leverages prior-breach data to pass identity-verification challenges.
Discovery
T1087.002/.003/.004Account Discovery (Domain/Email/Cloud) — enumerates AD, Entra ID groups and members.T1069.002/T1069.003Permission Groups Discovery — ADExplorer/ADRecon.ps1 for domain groups; Azure AD group membership.T1018Remote System Discovery — maps vCenter/ESXi infrastructure.T1046Network Service Discovery — RustScan port scanning.T1082/T1016/T1083System/Network/File Discovery — OS fingerprinting,ping/nltest, hunting MFA docs, network diagrams, and credentials.T1580/T1538Cloud Infrastructure Discovery — enumerates AWS S3 and Systems Manager Inventory.T1213.002/.003/.005Data from Information Repositories — SharePoint (VPN/MFA enrollment info), internal GitHub repos, Slack/Teams.
Lateral Movement
T1021.001RDP,T1021.004SSH (incl. vCenter),T1021.007Cloud Services (EC2/Azure).T1572Protocol Tunneling — Teleport.sh, Chisel, ngrok, Pinggy, MobaXterm SSH tunnels.T1090Proxy — proxy networks and rsocx reverse proxy to blend in.
Collection
T1530Data from Cloud Storage — OneDrive and cloud resources.T1114/T1114.003Email Collection / Forwarding Rule — searches Exchange for incident-response emails and forwards/redirects security alerts.T1074Data Staged — consolidates stolen data into a central store.
Command & Control
- RMM tools (
T1219.002) and tunnelers (T1572) double as resilient C2. ngrok (S0508) and Tor (S0183) appear in operations. T1578.002Modify Cloud Compute Infrastructure — spins up attacker EC2/Azure VMs as staging/C2.
Exfiltration
T1041Exfiltration Over C2 Channel — via Teleport.T1567.002Exfiltration to Cloud Storage — MEGA, AWS S3; abuse of cloud DB platforms (e.g., Snowflake tenants). Rclone (S1040) used for cloud transfer.
Impact
T1486Data Encrypted for Impact — BlackCat/ALPHV and later DragonForce ransomware, notably against VMware ESXi.T1490Inhibit System Recovery — stops Volume Shadow Copy service.T1006Direct Volume Access — shadow-copies DC disks to grab NTDS.dit.T1657Financial Theft — double-extortion: data theft + encryption with leak-site threats.
Signature tooling & malware
- Ransomware (RaaS affiliate, not owned): BlackCat/ALPHV (S1068), DragonForce, RansomHub, Qilin — deployed especially against ESXi.
- Credential tooling (public): Mimikatz (S0002), LaZagne (S0349), Impacket (S0357), Raccoon Stealer (S1148).
- Remote access / RMM (legitimate, abused): TeamViewer, AnyDesk, LogMeIn, ConnectWise ScreenConnect (S0591), Level RMM, Splashtop, Pulseway.
- Tunneling / C2: ngrok (S0508), Chisel, Teleport.sh, Pinggy, rsocx, MobaXterm, Tor (S0183).
- Recon / cloud: RustScan, ADExplorer, ADRecon.ps1, SharpHound, LinPEAS, aws_consoler.
- Exfil: Rclone (S1040), MEGA client.
- RATs / drivers: WarzoneRAT (S0670); BYOVD kernel driver (CVE-2015-2291).
- Hallmark: minimal custom malware — the group weaponizes legitimate admin/RMM software and identity systems, making it hard to catch with signature-based detection.
Emulation guidance (Decepticon)
Authorized use only: Execute the below exclusively within the documented rules of engagement and approved scope for this engagement; never SIM-swap real subscribers, social-engineer real third-party carriers/help desks outside scope, or deploy real ransomware against production data.
- Initial access via identity, not exploits. Lead with
defense-evasion/social-engineering playbooks emulating help-desk vishing and SSO smishing (T1598.004,T1660). Use the phishing/portal-cloning capability to stand up an in-scope lookalike SSO page (T1583.001) and harvest test credentials/OTPs. Emulate MFA fatigue (T1621) and attacker-MFA-device registration (T1098.005,T1556.006) against authorized test identities rather than performing a real SIM swap (T1451— emulate the OTP-interception outcome with a provisioned test number). - Cloud/identity pivot. Use the cloud skills (Azure/Entra + AWS) to emulate G1015's identity tradecraft: enumerate Entra ID/AWS accounts and groups (
T1087.004,T1069.003,T1580,T1538), add cloud credentials/roles (T1098.001,T1098.003), weaken Conditional Access / add trusted locations (T1556.009), and add a rogue federation trust (T1484.002) — all against the engagement's lab/test tenant. - AD operations. Drive the AD skills: ADExplorer/SharpHound-style enumeration (
T1069.002,T1087.002), DCSync and NTDS via shadow copy (T1003.006,T1003.003,T1006), Mimikatz/LaZagne dumping (T1003). Use bash/PowerShell forGet-ADUser,nltest, andpingrecon (T1059.001,T1016). - Lateral movement & C2. Use the lateral-movement skill for RDP/SSH/WMI (
T1021.001,T1021.004,T1047) and the c2/Sliver capability plus protocol tunneling (ngrok/Chisel-style,T1572,T1090) to mirror RMM-and-tunnel C2 (T1219.002). Deploy an approved RMM agent to a test host to replicate the signatureT1204→T1219.002chain. - Virtualization target. Where the lab includes VMware, emulate vCenter/ESXi enumeration and SSH access (
T1018,T1021.004) and group manipulation (T1098) — stop short of encryption; instead validate that backup/immutability controls would have blockedT1486/T1490. - Collection & exfil simulation. Stage benign canary data (
T1074) and exfiltrate to an in-scope cloud bucket via Rclone-style transfer (T1567.002) to test DLP/egress controls; emulate inbox-rule evasion (T1564.008,T1114.003) on a test mailbox. - Impact (simulated): For ransomware emulation, use a benign/inert payload or a detonation-safe simulator against test ESXi/hosts to exercise EDR-disable (
T1685), shadow-copy deletion (T1490), and encryption (T1486) detections — never real ransomware on production.
Detection & defense
- Identity verification at the help desk: require strong, out-of-band, on-camera or in-person verification before any password/MFA reset; never rely on DOB/last-4-SSN; temporarily disable self-service MFA resets during active threats. Directly counters
T1598.004/T1684.001. - Phishing-resistant MFA: remove SMS/voice/email factors; deploy FIDO2/number-matching; restrict MFA registration to trusted IPs/compliant devices; alert on the same MFA method registered across multiple users (counters
T1621,T1451,T1556.006,T1098.005). - Entra ID / SSO monitoring: alert on changes to Conditional Access Policies, Trusted Named Locations, and federation/domain config; verify all federated domains (counters
T1556.009,T1484.002). - Detect lookalike domains & smishing portals: continuous brand/typosquat domain monitoring; user training to reject MFA push-bombing and report IT-impersonation SMS/Teams messages (counters
T1583.001,T1660,T1598.001). - RMM control: allow-list approved remote-access software; alert on TeamViewer/AnyDesk/ScreenConnect/ngrok install or execution and outbound to tunneling services (counters
T1219.002,T1572). - Teams/collaboration detection: alert on external-tenant chats with display names containing "help"/"helpdesk" (Mandiant-provided KQL/SecOps rules).
- Recon tooling: alert on ADRecon, ADExplorer, SharpHound, RustScan execution; lock down docs containing VPN/MFA-enrollment/network-diagram info (counters discovery cluster).
- Identity store segregation & Tier-0: decouple AD from cloud/virtualization/backup identity; local, vault-excluded, MFA-enforced root accounts for ESXi/vCenter; enable ESXi lockdown mode; immutable, network-isolated backups (counters
T1486,T1490,T1003.x). - Egress restriction & session monitoring: restrict outbound from DCs/TSI servers; block Tor exit nodes and VPS ranges; alert on impossible-travel, proxy/VPN logins, and token replay (counters C2/exfil cluster).
Sources
- MITRE ATT&CK — Scattered Spider (G1015): https://attack.mitre.org/groups/G1015/
- Mandiant / Google Cloud — "Defending Against UNC3944: Cybercrime Hardening Guidance from the Frontlines": https://cloud.google.com/blog/topics/threat-intelligence/unc3944-proactive-hardening-recommendations
- CISA/FBI Joint Advisory AA23-320A — Scattered Spider: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a
- CISA alert — "CISA and Partners Release Updated Advisory on Scattered Spider Group" (July 29, 2025): https://www.cisa.gov/news-events/alerts/2025/07/29/cisa-and-partners-release-updated-advisory-scattered-spider-group
- IC3 PDF of AA23-320A (July 29, 2025): https://www.ic3.gov/CSA/2025/250729.pdf
- Group-IB — "Roasting 0ktapus: The phishing campaign going after Okta identity credentials": https://www.group-ib.com/blog/0ktapus/
- The Hacker News — "Scattered Spider Behind Cyberattacks on M&S and Co-op": https://thehackernews.com/2025/06/scattered-spider-behind-cyberattacks-on.html
- CSO Online — "Scattered Spider shifts focus to airlines": https://www.csoonline.com/article/4014787/scattered-spider-shifts-focus-to-airlines-as-strikes-hit-hawaiian-westjet-and-now-qantas.html
- Krebs on Security — "Alleged 'Scattered Spider' Member Extradited to U.S.": https://krebsonsecurity.com/2025/04/alleged-scattered-spider-member-extradited-to-u-s/