Threat actor · all actors
Scattered SpiderG1015 unknown
aka Scattered Spider, Roasted 0ktapus, Octo Tempest, Storm-0875, UNC3944, Muddled Libra, Oktapus, Scattered Swine, Scatter Swine, 0ktapus, Storm-0971, DEV-0971, Starfraud
Last updated: 2026-08-22
About this actor
[Scattered Spider](https://attack.mitre.org/groups/G1015) is a native English-speaking cybercriminal group active since at least 2022. (Citation: CrowdStrike Scattered Spider Profile) (Citation: MSTIC Octo Tempest Operations October 2023) The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. (Citation: MSTIC Octo Tempest Operations October 2023) [Scattered Spider](https://attack.mitre.org/groups/G1015) relies heavily on social engineering, including impersonating IT and help-desk staff, to gain initial access, bypass multi-factor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. (Citation: CISA Scattered Spider Advisory November 2023) (Citation: CrowdStrike Scattered Spider BYOVD January 2023) (Citation: Crowdstrike TELCO BPO Campaign December 2022) [Scattered Spider](https://attack.mitre.org/groups/G1015) had expanded into hybrid cloud and identity environments, using help-desk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365. (Citation: Mandiant UNC3944 May 2025)
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Microsoftweather-system names
CrowdStrikenation-animal names
MandiantUNC uncategorised cluster
Palo Alto Unit 42constellation names
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- Mixed — STIX + curated — 84 ATT&CK techniques on file.
- Named victims
- 3 extracted from reporting.
See how actor data is built for the full pipeline.
Activity timeline
- 2026 — 1 CVE published
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
CVE-2026-20929 | 5.9 | 7.5 | 0.0116 | 2026-01-13 | see CVE |
T1003OS Credential Dumping ↗T1003.003NTDS ↗T1006Direct Volume Access ↗T1016System Network Configuration Discovery ↗T1018Remote System Discovery ↗T1021Remote Services ↗T1021.001Remote Desktop Protocol ↗T1021.004SSH ↗T1021.007Cloud Services ↗T1041Exfiltration Over C2 Channel ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1059.004Unix Shell ↗T1068Exploitation for Privilege Escalation ↗T1069Permission Groups Discovery ↗T1069.002Domain Groups ↗T1070Indicator Removal ↗T1070.008Clear Mailbox Data ↗T1074Data Staged ↗T1078Valid Accounts ↗T1078.004Cloud Accounts ↗T1082System Information Discovery ↗T1083File and Directory Discovery ↗T1087Account Discovery ↗T1087.002Domain Account ↗T1090Proxy ↗T1098Account Manipulation ↗T1098.003Additional Cloud Roles ↗T1105Ingress Tool Transfer ↗T1114Email Collection ↗T1114.003Email Forwarding Rule ↗T1133External Remote Services ↗T1136Create Account ↗T1204User Execution ↗T1213Data from Information Repositories ↗T1213.003Code Repositories ↗T1213.005Messaging Applications ↗T1217Browser Information Discovery ↗T1219Remote Access Tools ↗T1219.002Remote Desktop Software ↗T1484Domain or Tenant Policy Modification ↗T1484.002Trust Modification ↗T1486Data Encrypted for Impact ↗T1490Inhibit System Recovery ↗T1530Data from Cloud Storage ↗T1538Cloud Service Dashboard ↗T1539Steal Web Session Cookie ↗T1543Create or Modify System Process ↗T1543.002Systemd Service ↗T1552Unsecured Credentials ↗T1552.001Credentials In Files ↗T1552.004Private Keys ↗T1553Subvert Trust Controls ↗T1553.002Code Signing ↗T1555Credentials from Password Stores ↗T1555.005Password Managers ↗T1556Modify Authentication Process ↗T1556.006Multi-Factor Authentication ↗T1556.009Conditional Access Policies ↗T1564Hide Artifacts ↗T1564.008Email Hiding Rules ↗T1566.004Spearphishing Voice ↗T1567Exfiltration Over Web Service ↗T1567.002Exfiltration to Cloud Storage ↗T1572Protocol Tunneling ↗T1578Modify Cloud Compute Infrastructure ↗T1578.002Create Cloud Instance ↗T1580Cloud Infrastructure Discovery ↗T1583Acquire Infrastructure ↗T1583.001Domains ↗T1585Establish Accounts ↗T1585.001Social Media Accounts ↗T1588Obtain Capabilities ↗T1588.001Malware ↗T1588.002Tool ↗T1589Gather Victim Identity Information ↗T1598Phishing for Information ↗T1598.003Spearphishing Link ↗T1598.004Spearphishing Voice ↗T1621Multi-Factor Authentication Request Generation ↗T1657Financial Theft ↗T1684Social Engineering ↗T1684.001Impersonation ↗T1685Disable or Modify Tools ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 51 / 84 | 61% |
AC-3 | 45 / 84 | 54% |
AC-6 | 44 / 84 | 52% |
CM-6 | 44 / 84 | 52% |
AC-2 | 42 / 84 | 50% |
CM-2 | 38 / 84 | 45% |
IA-2 | 36 / 84 | 43% |
AC-5 | 31 / 84 | 37% |
CA-7 | 30 / 84 | 36% |
CM-7 | 29 / 84 | 35% |
SI-7 | 29 / 84 | 35% |
CM-5 | 27 / 84 | 32% |
AC-4 | 26 / 84 | 31% |
SI-3 | 24 / 84 | 29% |
IA-5 | 22 / 84 | 26% |
Co-occurring actors
- Ajax Security Team 1 shared CVEs
- APT29 1 shared CVEs
- APT38 1 shared CVEs
- Sandworm Team 1 shared CVEs
- Tonto Team 1 shared CVEs
- GOLD SOUTHFIELD 1 shared CVEs
- OilRig 1 shared CVEs
- Indrik Spider 1 shared CVEs
- Mustang Panda 1 shared CVEs
- SolarWinds Compromise 1 shared CVEs
Similar actors
Similar TTPs
- LAPSUS$ 0.32
- C0027 0.29
- VOID MANTICORE 0.28
- Storm-0501 0.27
- SolarWinds Compromise 0.26
Active in same years
- Operation Dream Job 1.00
- SolarWinds Compromise 1.00
- C0027 1.00
- SharePoint ToolShell Exploitation 1.00
- Ke3chang 1.00