1attributed CVEs
42ATT&CK techniques
1.2IDF score (tooling uniqueness)
0exclusive CVEs
2026years active
About this actor
[C0027](https://attack.mitre.org/campaigns/C0027) was a financially-motivated campaign linked to [Scattered Spider](https://attack.mitre.org/groups/G1015) that targeted telecommunications and business process outsourcing (BPO) companies from at least June through December of 2022. During [C0027](https://attack.mitre.org/campaigns/C0027) [Scattered Spider](https://attack.mitre.org/groups/G1015) used various forms of social engineering, performed SIM swapping, and attempted to leverage access from victim environments to mobile carrier networks.(Citation: Crowdstrike TELCO BPO Campaign December 2022)
Source: MITRE ATT&CK
How we know this
- Data origin
- MITRE ATT&CK campaign Imported from the MITRE ATT&CK STIX bundle as a campaign object.
- Techniques
- MITRE ATT&CK STIX mappings — 42 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
- 2026 — 1 CVE published
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
CVE-2026-20929 | 5.9 | 7.5 | 0.0116 | 2026-01-13 | see CVE |
T1003OS Credential Dumping ↗T1003.006DCSync ↗T1021Remote Services ↗T1021.007Cloud Services ↗T1046Network Service Discovery ↗T1047Windows Management Instrumentation ↗T1069Permission Groups Discovery ↗T1069.003Cloud Groups ↗T1078Valid Accounts ↗T1078.004Cloud Accounts ↗T1087Account Discovery ↗T1087.003Email Account ↗T1087.004Cloud Account ↗T1090Proxy ↗T1098Account Manipulation ↗T1098.001Additional Cloud Credentials ↗T1098.003Additional Cloud Roles ↗T1098.005Device Registration ↗T1102Web Service ↗T1105Ingress Tool Transfer ↗T1133External Remote Services ↗T1190Exploit Public-Facing Application ↗T1213Data from Information Repositories ↗T1213.002Sharepoint ↗T1219Remote Access Tools ↗T1219.002Remote Desktop Software ↗T1530Data from Cloud Storage ↗T1566Phishing ↗T1566.004Spearphishing Voice ↗T1572Protocol Tunneling ↗T1578Modify Cloud Compute Infrastructure ↗T1578.002Create Cloud Instance ↗T1588Obtain Capabilities ↗T1588.002Tool ↗T1589Gather Victim Identity Information ↗T1589.001Credentials ↗T1598Phishing for Information ↗T1598.001Spearphishing Service ↗T1598.004Spearphishing Voice ↗T1621Multi-Factor Authentication Request Generation ↗T1684Social Engineering ↗T1684.001Impersonation ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 26 / 42 | 62% |
CM-6 | 24 / 42 | 57% |
AC-3 | 22 / 42 | 52% |
AC-2 | 20 / 42 | 48% |
AC-6 | 20 / 42 | 48% |
CM-7 | 19 / 42 | 45% |
IA-2 | 19 / 42 | 45% |
AC-4 | 18 / 42 | 43% |
AC-5 | 18 / 42 | 43% |
CM-2 | 18 / 42 | 43% |
CA-7 | 17 / 42 | 40% |
CM-5 | 17 / 42 | 40% |
SC-7 | 15 / 42 | 36% |
SI-3 | 13 / 42 | 31% |
IA-5 | 11 / 42 | 26% |
Co-occurring actors
- Ajax Security Team 1 shared CVEs
- APT29 1 shared CVEs
- APT38 1 shared CVEs
- Sandworm Team 1 shared CVEs
- Tonto Team 1 shared CVEs
- GOLD SOUTHFIELD 1 shared CVEs
- Scattered Spider 1 shared CVEs
- OilRig 1 shared CVEs
- Indrik Spider 1 shared CVEs
- Mustang Panda 1 shared CVEs
Similar actors
Similar TTPs
- LAPSUS$ 0.30
- Scattered Spider 0.29
- VOID MANTICORE 0.21
- Storm-0501 0.20
- INC Ransom 0.19
Overlapping CVEs
- APT12 1.00
- APT28 1.00
- FIN7 1.00
- OilRig 1.00
- Tropic Trooper 1.00
Active in same years
- Operation Dream Job 1.00
- SolarWinds Compromise 1.00
- SharePoint ToolShell Exploitation 1.00
- Ke3chang 1.00
- APT12 1.00