Dalton Hunter
Threat Actor Profile
Dalton Hunter
August 2026
Threat Actor Profile: Identity-Centric Cybercrime Collective

Scattered Spider

aka UNC3944 · Octo Tempest · Muddled Libra · allied as "Scattered Lapsus$ Hunters"

A loosely affiliated, largely English-speaking cybercrime collective operating out of "The Com" since 2022, known for bypassing MFA entirely by social-engineering help desks over the phone. Since 2025 it has paired that tradecraft with DragonForce ransomware for double extortion.

Threat Level: Critical
2022
First observed
£270–440M
Est. cost, Apr 2025 UK retail wave
6+
Vendor aliases, one collective
Jul '25
Latest joint gov't advisory
4
UK arrests, Jul 2025
Section 01

Actor Profile

Origin & structure

Scattered Spider emerged from "The Com," a decentralized online community skewing young, mostly teenagers and young adults across the US, UK, and other English-speaking countries. It first drew attention in mid-2022 running SIM-swap campaigns against telecom and BPO firms, including a breach of roughly 125 Twilio customers. The same operators are tracked under several vendor names: CrowdStrike's Scattered Spider, Mandiant's UNC3944, and Microsoft's Octo Tempest among them.

Targeting philosophy

The group works in sector-focused waves, concentrating on one industry for weeks before rotating: telecom/BPO (2022), gaming and hospitality (2023, including MGM and Caesars), financial services (late 2023), then a 2025 run through UK/US retail, insurance, aviation, and automotive. ReliaQuest's analysis of 600+ linked domains found about 70% of targets fall in technology, finance, and retail trade, with 81% of phishing domains impersonating a tech vendor or SSO provider.

Extortion model

Early campaigns favored pure data-theft extortion with no encryption. The group has since worked as an affiliate of ALPHV/BlackCat and RansomHub, and since early 2025 has partnered with the DragonForce ransomware cartel for double extortion. Its 2025 "Scattered Lapsus$ Hunters" branding with ShinyHunters and Lapsus$ points to a further shift toward large-scale SaaS data extortion.

Section 02

Timeline of Activity

Jun 2022

First tracked activity

CrowdStrike tracks SIM-swap campaigns against telecom and BPO firms, including a breach of roughly 125 Twilio customers.

Sep 2023

MGM Resorts & Caesars breaches

A help-desk vishing call gets the group into MGM; both MGM and Caesars are hit within weeks, alongside ALPHV/BlackCat ransomware.

2024

Pivot into SaaS and cloud

Mandiant documents direct targeting of vCenter, CyberArk, Salesforce, Azure, AWS, and GCP via stolen SSO credentials.

Apr–May 2025

UK retail wave

Vishing hits Marks & Spencer, then Co-op and Harrods; M&S loses NTDS.dit hashes and confirms DragonForce ransomware.

Jun–Jul 2025

Insurance and aviation waves

Targeting rotates to US insurers, then airlines including Hawaiian Airlines, WestJet, and Qantas.

Jul 2025

Joint advisory update & UK arrests

CISA and international partners update their joint advisory; the UK's NCA arrests four individuals tied to the retail wave.

Sep 2025

Jaguar Land Rover & "Scattered Lapsus$ Hunters"

JLR halts production after a breach jointly claimed with ShinyHunters; the groups begin branding together publicly.

May 2026

Ransomware activity resumes against insurers

CrowdStrike documents the group returning to aggressive ransomware operations against insurers after a pause.

Section 03

Kill Chain & MITRE ATT&CK Mapping

Scattered Spider's kill chain depends little on malware. The group's edge is convincing a person to hand over access, then living off legitimate remote-access tools once inside. Its technical footprint stays thin by design, though two real vulnerabilities have intersected with its campaigns: a critical SAP NetWeaver flaw (CVE-2025-31324) tied to the Jaguar Land Rover breach, and a VMware ESXi authentication-bypass technique (CVE-2024-37085) used to pivot stolen domain access into virtualization management.

01

Initial Access

Phishing for Information & Impersonation

Operators call IT help desks directly, impersonating a locked-out employee. They routinely answer identity-verification questions correctly, pointing to pre-call research on the target.

MFA Request Generation

Push-bombing pressures both victims and help-desk staff into approving a fraudulent MFA device during a live call.

Valid Accounts

SIM-swapping intercepts SMS-based MFA and reset codes, alongside typosquatted SSO and VPN phishing kits.

02

Execution & Persistence

Remote Access Software

Commercial RMM tools like AnyDesk, ScreenConnect, and TeamViewer establish persistence that looks like ordinary IT tooling.

Modify Authentication Process

New MFA devices are registered under compromised identities, surviving a routine password reset.

03

Privilege Escalation & Evasion

Impair Defenses (BYOVD)

A signed but vulnerable driver (POORTRY), delivered via a loader (STONESTOP), kills EDR and AV at the kernel level.

Valid Cloud Accounts

Once inside identity infrastructure, the group pivots directly into SaaS and cloud consoles, including vCenter, Salesforce, Azure, and AWS.

04

Credential Access & Lateral Movement

DCSync & Credential Dumping

Mimikatz and Impacket's secretsdump extract and replicate domain credentials once a privileged foothold is established.

AD Discovery & Lateral Movement

SharpHound and BloodHound map attack paths toward Domain Admin, then RDP and SSH move the operator laterally.

05

Command & Control / Exfiltration

Protocol Tunneling

Ngrok and Tailscale proxy C2 traffic through infrastructure that looks like ordinary developer tooling.

Exfiltration to Cloud Storage

Data is staged to MEGA or attacker-controlled S3 buckets ahead of any ransomware deployment.

06

Impact

Inhibit System Recovery

Backup infrastructure and virtualization management are targeted and shut down ahead of encryption to remove recovery options.

Data Encrypted for Impact

DragonForce ransomware, cross-platform across Windows, Linux, and ESXi, follows the exfiltration stage.

Tooling & named artifacts

Mimikatz Impacket / secretsdump SharpHound / BloodHound AnyDesk / ScreenConnect / TeamViewer Ngrok / Tailscale POORTRY / STONESTOP DragonForce ransomware MEGA / Amazon S3
Section 04

Indicators of Compromise

Scattered Spider's phishing infrastructure and tooling turn over fast, with individual pages taken down within 30 minutes of registration. What follows are durable, publicly reported patterns rather than a point-in-time list.

Reported patterns & behavior

Indicator / BehaviorTypeNotes
POORTRYSigned malicious driverDelivered via the STONESTOP loader to kill EDR/AV at kernel level
Typosquat SSO/helpdesk domainsDomain pattern~81% of tracked phishing domains impersonate a tech vendor
NTDS.dit exfiltrationBehaviorDomain password-hash theft confirmed in the M&S incident
New MFA device after resetBehaviorNew authenticator registered right after a help-desk reset call
Section 05

Detection & Mitigation Priorities

Ordered by impact-to-effort ratio for a mid-sized enterprise.

  • P1Harden help-desk identity verification with call-back or manager attestation before any password reset or MFA re-enrollment.
  • P1Deploy phishing-resistant MFA (FIDO2/WebAuthn) on all SSO, VPN, and privileged accounts.
  • P1Alert on new MFA device enrollment immediately following a help-desk password reset.
  • P2Restrict and monitor RMM tool usage via allow-listing rather than treating it as trusted by default.
  • P2Move backup and virtualization management off the domain, behind dedicated, non-domain credentials.
  • P3Baseline and alert on DCSync-style requests and BloodHound-style AD enumeration from non-admin hosts.
Section 06

References