Scattered Spider
A loosely affiliated, largely English-speaking cybercrime collective operating out of "The Com" since 2022, known for bypassing MFA entirely by social-engineering help desks over the phone. Since 2025 it has paired that tradecraft with DragonForce ransomware for double extortion.
Actor Profile
Origin & structure
Scattered Spider emerged from "The Com," a decentralized online community skewing young, mostly teenagers and young adults across the US, UK, and other English-speaking countries. It first drew attention in mid-2022 running SIM-swap campaigns against telecom and BPO firms, including a breach of roughly 125 Twilio customers. The same operators are tracked under several vendor names: CrowdStrike's Scattered Spider, Mandiant's UNC3944, and Microsoft's Octo Tempest among them.
Targeting philosophy
The group works in sector-focused waves, concentrating on one industry for weeks before rotating: telecom/BPO (2022), gaming and hospitality (2023, including MGM and Caesars), financial services (late 2023), then a 2025 run through UK/US retail, insurance, aviation, and automotive. ReliaQuest's analysis of 600+ linked domains found about 70% of targets fall in technology, finance, and retail trade, with 81% of phishing domains impersonating a tech vendor or SSO provider.
Extortion model
Early campaigns favored pure data-theft extortion with no encryption. The group has since worked as an affiliate of ALPHV/BlackCat and RansomHub, and since early 2025 has partnered with the DragonForce ransomware cartel for double extortion. Its 2025 "Scattered Lapsus$ Hunters" branding with ShinyHunters and Lapsus$ points to a further shift toward large-scale SaaS data extortion.
Timeline of Activity
First tracked activity
CrowdStrike tracks SIM-swap campaigns against telecom and BPO firms, including a breach of roughly 125 Twilio customers.
MGM Resorts & Caesars breaches
A help-desk vishing call gets the group into MGM; both MGM and Caesars are hit within weeks, alongside ALPHV/BlackCat ransomware.
Pivot into SaaS and cloud
Mandiant documents direct targeting of vCenter, CyberArk, Salesforce, Azure, AWS, and GCP via stolen SSO credentials.
UK retail wave
Vishing hits Marks & Spencer, then Co-op and Harrods; M&S loses NTDS.dit hashes and confirms DragonForce ransomware.
Insurance and aviation waves
Targeting rotates to US insurers, then airlines including Hawaiian Airlines, WestJet, and Qantas.
Joint advisory update & UK arrests
CISA and international partners update their joint advisory; the UK's NCA arrests four individuals tied to the retail wave.
Jaguar Land Rover & "Scattered Lapsus$ Hunters"
JLR halts production after a breach jointly claimed with ShinyHunters; the groups begin branding together publicly.
Ransomware activity resumes against insurers
CrowdStrike documents the group returning to aggressive ransomware operations against insurers after a pause.
Kill Chain & MITRE ATT&CK Mapping
Scattered Spider's kill chain depends little on malware. The group's edge is convincing a person to hand over access, then living off legitimate remote-access tools once inside. Its technical footprint stays thin by design, though two real vulnerabilities have intersected with its campaigns: a critical SAP NetWeaver flaw (CVE-2025-31324) tied to the Jaguar Land Rover breach, and a VMware ESXi authentication-bypass technique (CVE-2024-37085) used to pivot stolen domain access into virtualization management.
Initial Access
Operators call IT help desks directly, impersonating a locked-out employee. They routinely answer identity-verification questions correctly, pointing to pre-call research on the target.
Push-bombing pressures both victims and help-desk staff into approving a fraudulent MFA device during a live call.
SIM-swapping intercepts SMS-based MFA and reset codes, alongside typosquatted SSO and VPN phishing kits.
Execution & Persistence
Commercial RMM tools like AnyDesk, ScreenConnect, and TeamViewer establish persistence that looks like ordinary IT tooling.
New MFA devices are registered under compromised identities, surviving a routine password reset.
Privilege Escalation & Evasion
A signed but vulnerable driver (POORTRY), delivered via a loader (STONESTOP), kills EDR and AV at the kernel level.
Once inside identity infrastructure, the group pivots directly into SaaS and cloud consoles, including vCenter, Salesforce, Azure, and AWS.
Credential Access & Lateral Movement
Mimikatz and Impacket's secretsdump extract and replicate domain credentials once a privileged foothold is established.
SharpHound and BloodHound map attack paths toward Domain Admin, then RDP and SSH move the operator laterally.
Command & Control / Exfiltration
Ngrok and Tailscale proxy C2 traffic through infrastructure that looks like ordinary developer tooling.
Data is staged to MEGA or attacker-controlled S3 buckets ahead of any ransomware deployment.
Impact
Backup infrastructure and virtualization management are targeted and shut down ahead of encryption to remove recovery options.
DragonForce ransomware, cross-platform across Windows, Linux, and ESXi, follows the exfiltration stage.
Tooling & named artifacts
Indicators of Compromise
Scattered Spider's phishing infrastructure and tooling turn over fast, with individual pages taken down within 30 minutes of registration. What follows are durable, publicly reported patterns rather than a point-in-time list.
Reported patterns & behavior
| Indicator / Behavior | Type | Notes |
|---|---|---|
| POORTRY | Signed malicious driver | Delivered via the STONESTOP loader to kill EDR/AV at kernel level |
| Typosquat SSO/helpdesk domains | Domain pattern | ~81% of tracked phishing domains impersonate a tech vendor |
| NTDS.dit exfiltration | Behavior | Domain password-hash theft confirmed in the M&S incident |
| New MFA device after reset | Behavior | New authenticator registered right after a help-desk reset call |
Detection & Mitigation Priorities
Ordered by impact-to-effort ratio for a mid-sized enterprise.
- P1Harden help-desk identity verification with call-back or manager attestation before any password reset or MFA re-enrollment.
- P1Deploy phishing-resistant MFA (FIDO2/WebAuthn) on all SSO, VPN, and privileged accounts.
- P1Alert on new MFA device enrollment immediately following a help-desk password reset.
- P2Restrict and monitor RMM tool usage via allow-listing rather than treating it as trusted by default.
- P2Move backup and virtualization management off the domain, behind dedicated, non-domain credentials.
- P3Baseline and alert on DCSync-style requests and BloodHound-style AD enumeration from non-admin hosts.
References
- 01Scattered Spider: Joint Cybersecurity Advisory AA23-320A (updated Jul 2025)CISA / FBI / NCSC-UK / ACSC / RCMP
- 02Scattered Spider, UNC3944, Octo Tempest: Group G1015MITRE ATT&CK
- 03Scattered Spider: TTPs, MGM Attack & DefensesGroup-IB
- 04CrowdStrike 2026 Financial Services Threat Landscape ReportCrowdStrike
- 05Four Arrested in £440M Cyber Attack on Marks & Spencer, Co-op, and HarrodsThe Hacker News
- 06The DragonForce Cartel: Scattered Spider at the GateAcronis
- 07Scattered Spider Targets Tech Companies for Help-Desk ExploitationReliaQuest