Scattered Spider
Also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, UNC3944
Scattered Spider is a native English-speaking cybercriminal group active since at least 2022. The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. Scattered Spider relies heavily on social engineering, including impersonating IT and help-desk staff, to gain initial access, bypass multi-factor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. Scattered Spider had expanded into hybrid cloud and identity environments, using help-desk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365.
- Documented techniques
- 64
- Assessed motivation
- Financial gain
- First seen
- 2022
- Basis
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, grouped by the stage of an attack they belong to. This is the actionable half: each one is a behaviour you can look for in your own logs, and a control you can test.
reconnaissance4
resource development4
persistence5
privilege escalation1
credential access6
discovery11
- T1016 System Network Configuration Discovery
- T1018 Remote System Discovery
- T1069 Permission Groups Discovery
- T1069.002 Domain Groups
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1087 Account Discovery
- T1087.002 Domain Account
- T1217 Browser Information Discovery
- T1538 Cloud Service Dashboard
- T1580 Cloud Infrastructure Discovery
collection6
command and control4
defense impairment6
Malware
Families MITRE records this group deploying. Detection names for these are a reasonable place to start.
Tools
Legitimate or dual-use software the group is documented using. Most of it is software your own administrators use too, which is the point.