ThreatBox · Threat Actor Attribution
Scattered Spider
a.k.a. UNC3944, 0ktapus, Scatter Swine, Muddled Libra, Octo Tempest
Financial (Ransomware affiliate + extortion) USA / UK (English-speaking, mostly teenagers) First seen 2022
Scattered Spider is a native-English-speaking cybercrime group known for aggressive social-engineering of IT helpdesks. Members are often teenagers/young adults working with the Com/Comm subculture. They pioneered SIM-swapping + MFA-fatigue + helpdesk impersonation to reset MFA. High-profile 2023 hits: Caesars ($15M paid), MGM Resorts ($100M+ impact), Clorox, Reddit. Frequently affiliates with ALPHV/BlackCat and RansomHub for the encryption stage.
Targeted sectors
HospitalityGaming (casinos)RetailTelecomBPO
Targeted regions
North AmericaUK
Known TTPs (5)
T1566.004Spearphishing Voice (vishing)
T1621Multi-Factor Authentication Request Generation (MFA fatigue)
T1098.005Device Registration
T1078.004Valid Cloud Accounts
T1486Data Encrypted for Impact
Click any technique to open the MITRE ATT&CK reference.
Attack Timeline
- 2022-080ktapus phishing campaign (Twilio, Cloudflare, DoorDash)
- 2023-09MGM Resorts breach — casino floors offline for 10 days
- 2023-09Caesars Entertainment $15M ransom paid
- 2024-065 members charged by DOJ; UK arrests follow
- 2025-04Marks & Spencer / Co-op UK retail wave
Related Incidents from NivX Threat Intel (1)
critical
Scattered Spider Help-Desk Social Engineering
Threat actor impersonated employees to a service desk, reset MFA, and pivoted to cloud identity provider. NivX identity analytics flagged impossible-travel sign-ins minutes before privilege escalation.
Identity / Social Engineering
Incident case studies live in NivX Threat Intel, linked to this ThreatBox dossier by
actor_slug.References
End of dossier · Scattered Spider
Back to ThreatBox