PLAYBOOKSNETHOSTATTRIBDETECT
← all playbooks
THREAT ACTOR · eCRIME
Scattered Spider
Young, English-speaking, financially motivated, and terrifyingly effective. They don't exploit software. They call your help desk, impersonate an employee, reset the password, bypass MFA, and own your identity infrastructure before your SOC sees a single alert. The group that proved social engineering scales.
MITRE G1015 · US/UK-based · active 2022-present · $100M+ MGM · $15M Caesars · M&S/Co-op/Harrods 2025
Also known as
UNC3944 Octo Tempest Storm-0875 Muddled Libra 0ktapus Scatter Swine Star Blizzard
Why this group matters

Scattered Spider is not a single group. It's a collective of loosely affiliated subclusters that share TTPs, infrastructure patterns, and targeting philosophy. What connects them: native English speakers (mostly US and UK, many teenagers and young adults), identity-provider targeting as the primary attack vector, and the willingness to pick up the phone and lie convincingly to your help desk.

Their impact is disproportionate to their sophistication. They don't write zero-days. They don't deploy custom implants. They call the help desk, convince an IT staffer to reset a password, register a new MFA device, and then authenticate as a legitimate user. From there: Okta admin, Azure AD Global Admin, ESXi hypervisor, ransomware deployed, data exfiltrated. MGM lost $100M+ and 10 days of casino floor operations. Caesars paid $15M. M&S, Co-op, and Harrods were hit in a coordinated wave in May 2025.

"What started as a run-of-the-mill SIM-swapping crew has morphed into a global threat." They've progressed from SIM swaps (2022) to mass credential harvesting via Oktapus (9,931 credentials from 130+ companies) to ransomware deployment via BlackCat/ALPHV to the current DragonForce partnership. 70% of their targets are in technology, finance, and retail. They increasingly target MSPs and IT contractors for one-to-many access.

Your biggest vulnerability is your help desk. Every major Scattered Spider intrusion started with a phone call. Not an exploit. Not a phishing email. A call to an IT help desk from someone who sounds like an employee, knows the employee's name, team, and manager, and asks for a password reset. If your help desk can reset passwords and MFA without rigorous identity verification that cannot be socially engineered, Scattered Spider can get in.
Attack chain

1. Reconnaissance. LinkedIn, corporate directories, leaked databases. Build a profile of the target employee: name, title, team, manager, corporate email format. For MSP targeting, identify which IT contractor has admin access to the target organization.

2. Initial access (social engineering). Call the help desk impersonating the employee. Request a password reset and MFA re-enrollment. Alternative vectors: SMS phishing (smishing) targeting Okta/SSO login pages, MFA fatigue (push bombing until the user approves), SIM swap to intercept SMS-based MFA codes, AiTM phishing via Evilginx to capture session tokens, or vishing the employee directly.

3. Identity provider takeover. Once in, they target the identity provider (Okta, Azure AD/Entra ID). Create or modify admin accounts. Disable security controls. Add their own MFA devices. Modify conditional access policies. At this point, they control who can authenticate and how.

4. Persistence and lateral movement. Deploy RMM tools (AnyDesk, ScreenConnect, Splashtop) for persistent access. Move laterally via RDP, SSH, WMI. Target VMware ESXi hypervisors, domain controllers, and backup infrastructure. Use LOTL techniques to avoid endpoint detection.

5. Data theft and ransomware. Exfiltrate sensitive data for double extortion. Deploy ransomware (currently DragonForce, previously BlackCat/ALPHV, RansomHub). Target ESXi to encrypt all VMs simultaneously. The ransomware is the commodity tool. The social engineering is the craft.

Hunt checklist: if you suspect Scattered Spider
  1. 1. Audit help desk interactions for the past 72 hours Check for: password reset requests, MFA re-enrollment, account unlock requests, and new device registrations. Cross-reference with the user: did they actually make the request? Contact the user directly (not via email, which may be compromised). If the user didn't request the reset, the intrusion has already begun. Help desk ticketing system · Okta/Entra ID: MFA registration events
  2. 2. Check for new MFA device registrations Search identity provider logs for new authenticator app registrations, new phone numbers, new FIDO keys. Scattered Spider registers their own MFA device immediately after the social-engineered password reset. A new MFA method registered within minutes of a help desk-initiated reset is the signature pattern. Entra ID: "User registered security info" · Okta: system.mfa.factor.activate
  3. 3. Check for identity provider admin modifications Okta admin role assignments, Azure AD Global Admin grants, conditional access policy changes, new application consents. Scattered Spider escalates to identity provider admin as fast as possible because it gives them control over every downstream authentication decision. Okta: system.org.rate_limit.violation · Entra ID: directory audit logs
  4. 4. Hunt for unauthorized RMM tools Search for: AnyDesk, ScreenConnect (ConnectWise), Splashtop, TeamViewer, Atera, Level.io. Scattered Spider deploys RMM tools for persistent access that bypasses VPN and corporate authentication. Any RMM tool not on your approved software list, especially one installed after a suspicious help desk interaction, is high-confidence Scattered Spider. Sysmon EID 1: RMM binary execution · EID 3: connections to RMM cloud infra
  5. 5. Check for ESXi hypervisor access Scattered Spider targets ESXi directly (SSH to ESXi, vCenter access) to deploy ransomware on the hypervisor layer, encrypting all hosted VMs simultaneously. Check for: SSH connections to ESXi hosts, new ESXi local accounts, vCenter admin role assignments, and ransomware binaries (ELF format) in /vmfs/volumes/. Ransomware playbook · ESXi: /var/log/auth.log · vCenter audit logs
  6. 6. Check for MSP/contractor account abuse The M&S breach reportedly started through compromised accounts from IT contractor Tata Consultancy Services. Check for: unusual activity from MSP/vendor admin accounts, MSP accounts authenticating from unexpected IPs, and MSP-deployed RMM tools being used outside normal maintenance windows. Supply Chain playbook · MSP access audit logs
  7. 7. Check for credential harvesting phishing infrastructure Scattered Spider registers domains impersonating SSO, VPN, help desk, and Okta login pages. Domain patterns: keywords like "okta," "vpn," "helpdesk," "sso," "duo," "mfa," "servicenow" combined with the target company name. They've shifted from hyphenated domains (sso-company.com) to subdomain patterns (sso.company.com) to evade automated detection. Domain monitoring / DRP · Email gateway: inbound URLs matching SSO patterns
  8. 8. Look for data exfiltration before ransomware Scattered Spider exfiltrates data for double extortion before deploying ransomware. Check for: large outbound transfers to cloud storage, archive creation (7z, zip) on file servers, and unusual SharePoint/OneDrive download volumes from admin accounts. Data Exfiltration playbook · NET: Exfiltration
What distinguishes Scattered Spider

Social engineering first, always. Nation-state actors exploit software. Scattered Spider exploits people. Every major intrusion starts with a human interaction, not a technical vulnerability. This makes them uniquely hard to defend against with technical controls alone.

Native English speakers. Most APTs operate across language barriers (phishing in broken English, foreign accents on calls). Scattered Spider's members are native English speakers who sound exactly like the employees they're impersonating. This is why their help desk social engineering works where other groups' would fail.

RaaS affiliates, not operators. Scattered Spider doesn't write ransomware. They partner with RaaS platforms: BlackCat/ALPHV (2023), RansomHub (2024), DragonForce (2025). The ransomware is the commodity. The identity compromise chain is their value-add to the partnership.

Young, aggressive, and communicative. Members have been identified as teenagers and young adults. They communicate directly with victims (SMS, Telegram). Law enforcement has arrested several members, but operations continue uninterrupted. The collective structure means individual arrests don't stop the operation.

Related playbooks

Compromised Credentials (every Scattered Spider intrusion is a credential compromise)
Business Email Compromise (identity provider takeover enables mailbox access)
Ransomware Detected (ESXi deployment via DragonForce/BlackCat)
Insider Threat (help desk social engineering mimics insider access patterns)