Cyber Resilience

Threat actor · all actors

Scattered SpiderG1015 unknown

aka Scattered Spider, Roasted 0ktapus, Octo Tempest, Storm-0875, UNC3944, Muddled Libra, Oktapus, Scattered Swine, Scatter Swine, 0ktapus, Storm-0971, DEV-0971, Starfraud

Last updated: 2026-08-22

1attributed CVEs
84ATT&CK techniques
1.2IDF score (tooling uniqueness)
0exclusive CVEs
2026years active

About this actor

[Scattered Spider](https://attack.mitre.org/groups/G1015) is a native English-speaking cybercriminal group active since at least 2022. (Citation: CrowdStrike Scattered Spider Profile) (Citation: MSTIC Octo Tempest Operations October 2023) The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. (Citation: MSTIC Octo Tempest Operations October 2023) [Scattered Spider](https://attack.mitre.org/groups/G1015) relies heavily on social engineering, including impersonating IT and help-desk staff, to gain initial access, bypass multi-factor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. (Citation: CISA Scattered Spider Advisory November 2023) (Citation: CrowdStrike Scattered Spider BYOVD January 2023) (Citation: Crowdstrike TELCO BPO Campaign December 2022) [Scattered Spider](https://attack.mitre.org/groups/G1015) had expanded into hybrid cloud and identity environments, using help-desk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365. (Citation: Mandiant UNC3944 May 2025)

Source: MITRE ATT&CK

Names & naming systems

Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.

MITRE ATT&CKG-number catalogue id

G1015

Microsoftweather-system names

Octo TempestStorm-0875Storm-0971

CrowdStrikenation-animal names

Scattered Spider

MandiantUNC uncategorised cluster

UNC3944

Palo Alto Unit 42constellation names

Muddled Libra

Unclassifiedno scheme matched

Roasted 0ktapusOktapusScattered SwineScatter Swine0ktapusDEV-0971Starfraud

How we know this

Data origin
MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
Techniques
Mixed — STIX + curated — 84 ATT&CK techniques on file.
Named victims
3 extracted from reporting.

See how actor data is built for the full pipeline.

Activity timeline

Profile

CVERiskCVSSEPSSPublishedProducts
CVE-2026-20929 5.97.50.01162026-01-13see CVE

Mitigating controls (NIST 800-53)

ControlTechniques coveredCoverage
SI-451 / 8461%
AC-345 / 8454%
AC-644 / 8452%
CM-644 / 8452%
AC-242 / 8450%
CM-238 / 8445%
IA-236 / 8443%
AC-531 / 8437%
CA-730 / 8436%
CM-729 / 8435%
SI-729 / 8435%
CM-527 / 8432%
AC-426 / 8431%
SI-324 / 8429%
IA-522 / 8426%

Co-occurring actors

Similar actors

Overlapping CVEs