Back to ThreatBox
ThreatBox · Threat Actor Attribution

Scattered Spider

a.k.a. UNC3944, 0ktapus, Scatter Swine, Muddled Libra, Octo Tempest
Financial (Ransomware affiliate + extortion) USA / UK (English-speaking, mostly teenagers) First seen 2022

Scattered Spider is a native-English-speaking cybercrime group known for aggressive social-engineering of IT helpdesks. Members are often teenagers/young adults working with the Com/Comm subculture. They pioneered SIM-swapping + MFA-fatigue + helpdesk impersonation to reset MFA. High-profile 2023 hits: Caesars ($15M paid), MGM Resorts ($100M+ impact), Clorox, Reddit. Frequently affiliates with ALPHV/BlackCat and RansomHub for the encryption stage.

Targeted sectors
HospitalityGaming (casinos)RetailTelecomBPO
Targeted regions
North AmericaUK

Known TTPs (5)

Click any technique to open the MITRE ATT&CK reference.

Attack Timeline

  1. 2022-08
    0ktapus phishing campaign (Twilio, Cloudflare, DoorDash)
  2. 2023-09
    MGM Resorts breach — casino floors offline for 10 days
  3. 2023-09
    Caesars Entertainment $15M ransom paid
  4. 2024-06
    5 members charged by DOJ; UK arrests follow
  5. 2025-04
    Marks & Spencer / Co-op UK retail wave

Related Incidents from NivX Threat Intel (1)

critical
Scattered Spider Help-Desk Social Engineering
Threat actor impersonated employees to a service desk, reset MFA, and pivoted to cloud identity provider. NivX identity analytics flagged impossible-travel sign-ins minutes before privilege escalation.
Identity / Social Engineering
Incident case studies live in NivX Threat Intel, linked to this ThreatBox dossier by actor_slug.

References

End of dossier · Scattered Spider
Back to ThreatBox