TLP:CLEAR
⚠ ECRIME · INDEPENDENT / "THE COM" · US · UK · CANADA
// Threat Actor Profile — Social-Engineering-Driven Extortion & Ransomware Affiliate Collective

SCATTERED SPIDER

PROFILE COMPILED: 2026-08-30  |  PREVIOUSLY COMPILED: 2026-08-29  |  SOURCES: MITRE ATT&CK (G1015), CISA/FBI Joint Advisory AA23-320A, Google Cloud/Mandiant (UNC3944), CrowdStrike, Microsoft Threat Intelligence, Krebs on Security, CyberScoop, DOJ press materials, Team Cymru, Silent Push, GuidePoint Security, Halcyon, ReliaQuest, AttackIQ, MITRE CTID, Atomic Red Team, SigmaHQ, 20+ additional vendor/press sources
Status: ACTIVE — HIGH TEMPO, EXPANDING SECTOR FOCUS
Threat Level: CRITICAL
Primary Motive: Financial Extortion — Ransomware & Data-Theft Extortion
Active Since: May 2022
MITRE ATT&CK: G1015
⚡ THREAT UPDATE — AUG 2026
UK sentencing of two leaders and "ShinySp1d3r" RaaS build show reach outlives arrests
In September 2025, the U.S. DOJ charged Thalha Jubair (19, London) with conspiracies tied to at least 120 intrusions and $115M+ in extortion payments extracted from 47 U.S. entities between May 2022 and September 2025; Jubair and co-defendant Owen Flowers (18, Walsall) were arrested by UK police, pleaded guilty, and were sentenced in the UK to 66 months for the August 2024 Transport for London attack (Krebs on Security; CyberScoop, 2025–2026). Despite these convictions, the broader "Scattered LAPSUS$ Hunters" collective — merging Scattered Spider, LAPSUS$, and ShinyHunters branding and personnel — has continued high-tempo operations into 2026, including claimed access to a CrowdStrike-related internal dashboard and public development of a dedicated "ShinySp1d3r" ransomware-as-a-service platform (CYFIRMA, 2026). Vendor 2026 outlooks (Sophos, Trend Micro) assess healthcare as a likely next concentrated target.
120+
Intrusions Alleged Against a Single Charged Member, May 2022 – Sep 2025
$115M+
Ransom Payments Attributed to Two Charged UK Members
6
Major Industry Verticals Struck in Successive Waves During 2025 Alone
May 2022
Earliest Confirmed Activity — Telecom/BPO SIM-Swap Operations
00
Overview

Scattered Spider is a financially motivated, loosely affiliated eCrime collective active since at least May 2022, tracked across the industry under a sprawling list of aliases — UNC3944 (Mandiant/Google), Octo Tempest (Microsoft), Muddled Libra (Unit 42), Roasted 0ktapus and Scatter Swine (CrowdStrike and others) — and catalogued by MITRE ATT&CK as G1015. Rather than relying primarily on malware or novel exploits, the group has built one of the most effective social-engineering operations in modern cybercrime: impersonating employees and IT help-desk staff by phone (vishing) to trigger password and multi-factor-authentication (MFA) resets, bypassing identity controls that stop most purely technical intrusions.

The group's target list has expanded relentlessly since its 2022 origins in telecom-focused SIM-swapping: financial-services firms in late 2023, food-services and hospitality organizations by mid-2024, UK retailers — Marks & Spencer, Co-op, Harrods — in spring 2025, U.S. insurance carriers including Aflac in mid-2025, and the aviation sector — Qantas, Hawaiian Airlines, WestJet — in mid-2025. Each wave follows a similar pattern: concentrated targeting of a single vertical for several weeks before pivoting to the next, suggesting centralized target-selection despite the group's decentralized membership.

Scattered Spider is best understood as a persistent capability within a much larger cybercriminal ecosystem known as "The Com" — an English-speaking, largely Discord/Telegram-coordinated community of young hackers spanning the US, UK, and Canada that also produced LAPSUS$ and shares members, tooling, and tradecraft across brands (see companion profile: LAPSUS$). Since 2023 the group has operated as a flexible ransomware affiliate — deploying ALPHV/BlackCat, then RansomHub and Qilin, and by 2025 DragonForce — rather than building or maintaining its own leak infrastructure, and in 2025–2026 elements of Scattered Spider merged branding with LAPSUS$ and ShinyHunters under the "Scattered LAPSUS$ Hunters" umbrella.

The group matters now because arrests have proven only partially disruptive. U.S. and U.K. law enforcement charged and sentenced several alleged members through 2025 and into 2026, including a UK member linked to over 120 intrusions and $115M+ in ransom payments, yet the collective's loose, brand-fluid structure and deep bench within The Com have allowed activity to continue and even escalate — most notably a strategic pivot toward hijacking VMware ESXi/vSphere infrastructure to deploy ransomware directly from the hypervisor layer, a technique that bypasses most endpoint security entirely.

01
Identity & Attribution
Primary NameScattered Spider
Sponsor / ParentNone identified — independent criminal collective, loosely affiliated with "The Com"
Actor TypeeCrime — Social Engineering / Ransomware-as-a-Service Affiliate
Primary MotivationFinancial extortion via ransomware deployment and data-theft extortion
Active SinceMay 2022 (initial telecom/BPO SIM-swap operations)
Last Observed2026 — active under "Scattered LAPSUS$ Hunters" branding; ShinySp1d3r RaaS platform reported in development
MITRE G-IDG1015
Legal StatusMultiple UK/US arrests and charges, 2024–2025; Thalha Jubair and Owen Flowers sentenced in UK (66 months, TfL attack); DOJ complaint alleges 120+ intrusions, $115M+ extorted
Tracking Aliases
Scattered Spider UNC3944 Octo Tempest Muddled Libra Roasted 0ktapus 0ktapus Scatter Swine Storm-0875
Attribution Confidence

Attribution to a loosely organized collective of primarily young, native-English-speaking individuals based in the US, UK, and Canada is HIGH, supported by multiple independent law-enforcement actions (UK NCA/police, US DOJ/FBI) resulting in named arrests, guilty pleas, and sentencing tied to specific intrusions. However, "Scattered Spider" functions more as a shared tradecraft brand within The Com than a fixed membership roster — individual campaigns may involve different, overlapping sets of operators, and clean separation from affiliated brands (LAPSUS$, ShinyHunters, individual DragonForce affiliates) is not always possible.

02
Campaign & Operational Timeline
MAY 2022 –
EARLY 2023
Telecom & BPO SIM-Swap Origins
Emerges targeting telecommunications and business-process-outsourcing (BPO) firms, primarily to support SIM-swapping for cryptocurrency theft and account takeover. MITRE tracks this window as Campaign C0027 (Jun–Dec 2022), which included exploitation of CVE-2021-35464 in ForgeRock OpenAM against telecom victims.
SEP 2023
MGM Resorts & Caesars Entertainment
Vished a Caesars IT-support vendor and an MGM help desk to obtain credential/MFA resets; deployed ALPHV/BlackCat ransomware against MGM, triggering a week-long outage estimated to have cost the company roughly $100M; Caesars reportedly paid a ransom to avoid a data leak.
LATE 2023 –
2024
Financial Services & Food/Hospitality Waves
Shifts target focus to financial-services organizations in late 2023 and food-services/hospitality companies by mid-2024, continuing help-desk vishing as the primary initial-access vector. CISA and the FBI issue joint advisory AA23-320A (Nov 2023, later updated July 2025).
AUG 2024
Transport for London (TfL) Intrusion
Attack disrupts Transport for London systems and customer data; UK and US law enforcement later tie the intrusion to Owen Flowers and Thalha Jubair, both ultimately arrested and prosecuted.
APR – JUL
2025
UK Retail, US Insurance & Aviation Waves
Concentrated campaigns hit UK retailers (Marks & Spencer, Co-op, Harrods, plus Cartier, Victoria's Secret, Adidas), then US insurers (Aflac, Philadelphia Insurance, Erie Insurance) in June, then airlines (Qantas, Hawaiian Airlines, WestJet) in June–July. Parallel reporting describes a strategic pivot to hijacking VMware ESXi/vSphere infrastructure to deploy DragonForce ransomware directly from the hypervisor.
SEP 2025 –
2026
Arrests, Sentencing & "Scattered LAPSUS$ Hunters" Resurgence
UK arrests and US DOJ charges against Jubair and Flowers (Sep 2025); both plead guilty and are sentenced in the UK to 66 months. Despite this, the merged "Scattered LAPSUS$ Hunters" brand remains active into 2026, claiming access to CrowdStrike-related material and developing the "ShinySp1d3r" ransomware-as-a-service platform.
03
Attack Lifecycle Social engineering as the entire kill chain — not just the entry point

Scattered Spider's defining characteristic is that nearly its entire intrusion lifecycle can run through social engineering rather than malware. Initial access typically begins with reconnaissance on LinkedIn, breach-data marketplaces, and general OSINT to build a convincing profile of a real employee, followed by a phone call to the target organization's (or its MSP's) IT help desk in which an operator — often a native English speaker capable of mimicking regional accents — impersonates that employee to request a password reset or MFA re-enrollment (T1566.004, T1598.004, T1684.001). Where a live call is impractical, the group substitutes SMS phishing or fake corporate-login domains engineered to closely mirror the real single sign-on portal (T1583.001, T1598.003).

Once inside, the group avoids traditional malware wherever possible, instead abusing legitimate administrative tools and cloud consoles already present in the environment: registering its own MFA device to a compromised account (T1556.006), enumerating Active Directory and Azure AD/Entra ID via PowerShell and native tooling (T1087, T1069), and establishing remote access through commercial tools like TeamViewer, AnyDesk, and ngrok, or tunneling utilities such as Chisel and Teleport (T1219, T1572). Credential harvesting relies on tools like Mimikatz, LaZagne, and Raccoon Stealer, and where legitimate access alone is insufficient, the group has exploited specific vulnerabilities — CVE-2021-35464 in ForgeRock OpenAM, and a vulnerable-driver exploit chain (CVE-2015-2291) — for privilege escalation and EDR evasion.

Since 2024–2025, the group's most consequential evolution has been a pivot toward VMware vSphere/ESXi environments: after gaining Active Directory dominance, operators enumerate vCenter and ESXi hosts, deploy tools like RustScan and Impacket for lateral movement, and ultimately push ransomware — historically ALPHV/BlackCat, and by 2025, DragonForce — directly onto the hypervisor layer, encrypting virtual-machine datastores in bulk while bypassing guest-OS endpoint security almost entirely. Data exfiltration typically precedes encryption, using legitimate cloud-storage and transfer services (MEGA, Snowflake, AWS S3, Rclone) to support double extortion, and the group frequently harasses victim executives, employees, and even incident responders directly by phone and social media during negotiations — a psychological-pressure tactic distinct from most ransomware operators.

04
TTPs — MITRE ATT&CK Mapping Enterprise framework; mapped against G1015
Reconnaissance
T1589.001
Gather Victim Identity Information: Credentials
[HIGH] Collected OSINT and phished credentials via SMS to build convincing employee identity profiles ahead of vishing calls.
Resource Development
T1583.001
Acquire Infrastructure: Domains
[HIGH] Registered lookalike domains spoofing corporate SSO/Okta login portals for credential harvesting.
Initial Access
T1566.004
Phishing: Spearphishing Voice
[HIGH] Vished IT help-desk and MSP staff, impersonating employees to trigger password/MFA resets — the group's signature technique.
Initial Access
T1078.004
Valid Accounts: Cloud Accounts
[HIGH] Used compromised Microsoft Entra ID and Okta credentials obtained via social engineering for direct cloud-console access.
Persistence
T1098.005
Account Manipulation: Device Registration
[HIGH] Registered attacker-controlled devices for MFA and VPN access to survive password rotations.
Defense Evasion
T1068
Exploitation for Privilege Escalation
[MEDIUM] Deployed a malicious signed kernel driver via a BYOVD chain (CVE-2015-2291) to terminate EDR/security processes ahead of ransomware deployment.
Defense Evasion
T1564.008
Hide Artifacts: Email Hiding Rules
[MEDIUM] Created inbox rules and manually deleted security-alert emails to hide suspicious-activity notifications from victims.
Credential Access
T1003.006
OS Credential Dumping: DCSync
[HIGH] Performed DCSync domain-replication requests to extract Active Directory credentials at scale.
Discovery
T1069
Permission Groups Discovery
[HIGH] Enumerated vSphere/ESX Admin groups and Active Directory/Azure AD privileged groups to identify high-value targets.
Lateral Movement
T1021.004
Remote Services: SSH
[HIGH] Used SSH to reach and pivot through VMware vCenter Server Appliances after gaining AD-level access.
Exfiltration
T1567.002
Exfiltration Over Web Service: Cloud Storage
[HIGH] Exfiltrated victim data to MEGA, Snowflake, and AWS S3 ahead of encryption to support double-extortion negotiations.
Impact
T1486
Data Encrypted for Impact
[HIGH] Deployed ALPHV/BlackCat and, since 2025, DragonForce ransomware — including direct encryption of ESXi datastores from the hypervisor layer.
05
Targeting Profile
Sector Targeting
Retail, Hospitality & Gaming
PRIMARY
Insurance & Financial Services
HIGH
Aviation & Transportation
HIGH
Telecommunications & BPO
MED
Technology / SaaS / Identity Providers
MED
GeographiesPrimarily United States and United Kingdom; expanding activity against Australia (Qantas) and Canada-based organizations
Victim ProfileLarge enterprises with outsourced or offshored IT help desks/MSPs; organizations with immature help-desk identity-verification procedures; heavy VMware vSphere/ESXi virtualization footprints
Preferred EntryIT help-desk and MSP social engineering (vishing); SMS phishing; SIM swapping to intercept MFA/OTP; purchased or breach-derived employee PII used to pass identity verification
Target DoctrineOpportunistic within a chosen vertical — concentrates on one industry for several weeks to refine and reuse a working help-desk pretext, then pivots to a new sector once defenses adapt (retail → insurance → aviation pattern observed through 2025)
06
Tools, Malware & Infrastructure
DragonForce Ransomware Ransomware / RaaS Partner · Conti-Derived
Adopted as Scattered Spider's primary ransomware payload since 2025 following disruption of ALPHV/BlackCat. Encrypts Windows, Linux, and VMware ESXi datastores directly from the hypervisor, and is frequently paired with BYOVD kernel drivers (e.g., truesight.sys, rentdrv2.sys) to terminate EDR/AV processes before encryption begins.
Raccoon Stealer Infostealer · Commodity/Underground
Used to harvest browser-stored credentials, session cookies, and autofill data from compromised endpoints, feeding subsequent session-hijacking and lateral-movement operations without needing fresh credential-phishing.
Teleport / Chisel / ngrok Tunneling & Remote Access · Legitimate/Open-Source (Abused)
Deployed on compromised VMware vCenter Server Appliances and endpoints to establish covert, encrypted tunnels for C2 and data exfiltration; blends with legitimate DevOps/remote-access traffic and evades detection tuned for known malware signatures.
Mimikatz / LaZagne / Impacket Credential Theft & Lateral Movement · Open-Source
Standard post-exploitation toolkit used to dump credentials from memory and password stores and to execute WMI/SMB-based lateral movement across Windows domains once initial access is established.
aws_consoler / RustScan Cloud & Network Reconnaissance · Open-Source
aws_consoler converts stolen AWS API credentials into temporary federated console sessions; RustScan performs rapid port scanning of ESXi hosts and internal infrastructure to map attack surface ahead of lateral movement.
07
Indicators of Compromise All IPs and domains defanged
⚠ IOC HANDLING — All IPs and domains in this table are defanged. Reconstruct before use in detection tooling. Reference URLs in Section 13 are NOT defanged.
Type Value / Description Source Date
CVECVE-2021-35464 — ForgeRock OpenAM remote code execution, used for initial access against telecom victimsCISA AA23-320A2023-11-16
CVECVE-2024-37085 — VMware ESXi authentication-bypass, exploited to deploy rootkits and disable EDRGoogle Cloud / Security Affairs2025-07
MALWAREDragonForce ransomware paired with BYOVD drivers truesight[.]sys and rentdrv2[.]sys to terminate security processesAcronis TRU2025
TOOLngrok, Chisel, Teleport, AnyDesk, TeamViewer used as dual-use C2/tunneling tools — flag by anomalous behavior, not by static signatureMITRE ATT&CK G10152022–2026
NOTENo durable static IP/domain indicator list exists for this actor: Scattered Spider rotates lookalike SSO/login domains per engagement and relies heavily on legitimate/dual-use services (MEGA, Snowflake, AWS S3) rather than fixed C2 infrastructure. Defenders should prioritize the behavioral and identity-based indicators in Sections 04 and 06 over static IOCs, and consult CISA AA23-320A and current vendor threat-intel feeds for the latest domain patterns.
08
Analyst Assessment
Overall Threat LevelCRITICAL
Attribution ConfidenceHIGH (named-member level) / MEDIUM (ecosystem boundaries)
TrajectoryEscalating — sector pivots roughly every 1–2 months through 2025; continued operation into 2026 despite arrests; active RaaS-platform development (ShinySp1d3r)
Most Dangerous CapabilityDefeating mature MFA/identity programs through pure social engineering, then pivoting directly to hypervisor-level ransomware deployment that bypasses most endpoint security
Primary Intel GapTrue current membership and overlap boundaries with LAPSUS$/ShinyHunters under the "Scattered LAPSUS$ Hunters" brand; extent of insider-recruitment success
Ecosystem / Affiliated Groups
LAPSUS$ ShinyHunters "The Com" ALPHV/BlackCat RansomHub Qilin DragonForce

Scattered Spider represents a category of risk that most enterprise security programs are not built to counter: a well-resourced, financially motivated adversary whose primary attack surface is human trust in IT support processes rather than software vulnerabilities. Arrests have demonstrably disrupted specific individuals — the September 2025 charges against Thalha Jubair and Owen Flowers, and their subsequent guilty pleas and sentencing, removed operators tied to a documented $115M+ in extortion payments — but have not visibly slowed the broader brand's operational tempo, which continued through the 2025 aviation and insurance waves and into the 2026 "Scattered LAPSUS$ Hunters" resurgence.

The group's pivot to VMware ESXi/vSphere as a direct ransomware deployment surface is the most significant recent capability shift: it converts a single compromised set of AD-domain-admin-equivalent credentials into the ability to encrypt an entire virtualized estate at once, sidestepping guest-OS endpoint detection almost entirely. Combined with the group's established willingness to harass victims and responders directly during negotiations, this makes Scattered Spider incidents unusually fast-moving and organizationally disruptive compared to a typical ransomware-affiliate intrusion.

Competing hypotheses persist about how tightly "Scattered Spider," "LAPSUS$," and "ShinyHunters" should be treated as one entity versus three overlapping-but-distinct brands sharing a talent pool within The Com; this profile treats them as a shared ecosystem rather than a single organization, consistent with vendor practice (Google/Mandiant, Microsoft, and CrowdStrike each retain separate tracking designations). Confidence in the near-term trajectory would increase with corroborated evidence that the claimed ShinySp1d3r RaaS platform has reached operational status, and would decrease if 2026 law-enforcement actions beyond Jubair and Flowers meaningfully reduce the pool of experienced vishing operators — the group's actual scarce resource, given how replicable its non-malware tradecraft otherwise is.

09
Defensive Recommendations
01
Harden help-desk identity verification. Require call-back verification to a pre-registered number, video verification, or manager co-sign for any password/MFA reset request; train help-desk and MSP staff specifically on Scattered Spider's impersonation patterns.
Counters: T1566.004, T1684.001
02
Enforce phishing-resistant MFA. Move privileged and help-desk-resettable accounts to FIDO2/WebAuthn hardware keys, which are not vulnerable to MFA-fatigue prompt bombing or SIM-swap OTP interception.
Counters: T1621, Mobile T1451
03
Restrict and monitor MFA/device re-registration. Alert on and require secondary approval for new MFA-device enrollments or VPN device registrations, especially outside normal onboarding workflows.
Counters: T1098.005, T1556.006
04
Segment and harden vCenter/ESXi management planes. Isolate vSphere/vCenter management interfaces on dedicated, tightly access-controlled network segments; disable SSH on ESXi hosts by default and monitor for its activation.
Counters: T1021.004, T1046, T1486
05
Detect and block known BYOVD driver abuse. Deploy Microsoft's vulnerable-driver blocklist (or equivalent) and monitor for attempts to load unsigned or known-vulnerable kernel drivers used to disable EDR.
Counters: T1068
06
Monitor for legitimate-tool abuse, not just malware signatures. Alert on installation or execution of remote-access/tunneling tools (AnyDesk, TeamViewer, ngrok, Chisel) outside IT-managed baselines, and flag anomalous outbound traffic to MEGA, Snowflake, or personal cloud-storage endpoints from servers.
Counters: T1219, T1572, T1567.002
07
Audit cloud/Entra ID privileged-role assignment and federation changes. Alert on new federated identity-provider trust relationships added to SSO tenants and on unexpected privileged-role grants.
Counters: T1484.002, T1098.003
08
Maintain tested, offline/immutable backups covering hypervisor state, not just guest data. Ensure backup and recovery procedures explicitly cover ESXi/vCenter configuration, given the group's demonstrated hypervisor-layer encryption capability.
Counters: T1486, T1490
10
OPSEC Procedures Observed infrastructure hygiene, rotation patterns, anti-forensics
Infrastructure Rotation [HIGH]
Registrars and hosting providers behind lookalike SSO/login domains rotate heavily between campaigns — Silent Push has tracked the group's phishing infrastructure moving across Njalla-registered name servers and BitLaunch/DigitalOcean VPS instances sub-leased through BitLaunch to obscure the underlying provider relationship (Silent Push, 2024). Team Cymru's infrastructure-profiling work further documents the group deliberately authenticating from clean, non-VPN United States IP space rather than commercial VPN exit nodes, and layering residential-proxy networks on top of that — a specific effort to defeat geo-anomaly and known-VPN-ASN detection rules that flag logins from datacenter or foreign-exit infrastructure (Team Cymru, "Scattered Spider Attacks: Infrastructure and TTP Analysis").
Living-off-the-Land Ratio [MEDIUM]
Post-access tradecraft leans heavily on PowerShell-driven credential extraction and native registry manipulation rather than the classical LOLBAS set (certutil, mshta, wmic) — GuidePoint Security's forensic analysis documents extensive PowerShell scripting against privileged-access-management platforms (CyberArk, Thycotic) and a batch script that deletes multiple Windows Defender/Threat-Protection registry subkeys to disable native AV, notably reusing command syntax ("Worldwide Web: An Analysis of Tactics and Techniques Attributed to Scattered Spider," GuidePoint Security) that mirrors publicly posted Microsoft-forum "fix" guidance repurposed for defense evasion (see Section 11 for the specific command). This is combined with a distinct open-source/commercial toolset for lateral movement and tunneling (Impacket, Chisel, ngrok, Teleport) rather than bespoke malware for those functions.
Anti-Forensics [MEDIUM]
Kernel-level anti-forensics centers on the BYOVD toolkit STONESTOP (userland loader) and POORTRY (malicious signed driver), which Mandiant has tracked in Scattered Spider/UNC3944 intrusions since August 2022 and used specifically to unhook and terminate EDR/AV processes at the driver level, removing the forensic visibility those tools would otherwise provide (Mandiant, "Hunting for Attestation Signed Malware"; CrowdStrike). Separately, Halcyon reporting describes the group disabling Windows Defender, SentinelOne, and CrowdStrike agents via obfuscated scripts and direct system-service interaction, and in cloud/virtualized environments removing security agents and clearing logs using stolen or vendor-provided remote-access tooling over VPN. Neither source publishes the specific log-clearing commands or event-ID-level detail — the anti-forensics picture is well-evidenced at the "what was disabled" level but thin on precise operator syntax beyond the registry and driver specifics captured above.
Timing & Operational Patterns [MEDIUM]
Dwell time before destructive action varies considerably by engagement and appears deliberate rather than incidental: ReliaQuest's account-compromise analysis of the Marks & Spencer intrusion documents an approximately two-month dwell period between initial access and ransomware detonation, used to map the environment, stage exfiltration for double-extortion leverage, and position payloads for maximum simultaneous coverage before triggering encryption. This is a longer, more patient window than the group's compressed initial-access phase (help-desk vishing to credential reset can complete within minutes to hours), indicating the group modulates its operational tempo by phase — fast and aggressive at the social-engineering entry point, slower and more methodical during internal reconnaissance and staging.
Tooling Hygiene [MEDIUM]
The POORTRY driver has been observed signed with a mix of stolen, leaked, and repurposed code-signing certificates, including at least one variant masquerading as an Internet Download Manager TDI driver from Tonec Inc. and signed with an expired certificate issued to "Shanghai Yikaoda Information Consulting Co., Ltd." (Mandiant). Continued use and iteration of the same STONESTOP/POORTRY pairing from August 2022 through subsequent campaigns indicates a maintained, internally iterated capability rather than single-use tooling, even as the specific signing certificate is rotated per build to evade certificate-revocation and hash-based detection.
11
Detection Evasion Specific techniques, LOLBin sequences, EDR bypass patterns
Kernel-Level EDR/XDR Unhooking via BYOVD (STONESTOP/POORTRY) T1068 / T1562.001
EDR BYPASS STONESTOP · POORTRY · CVE-2015-2291
STONESTOP, a userland utility, loads the POORTRY malicious signed driver — sometimes via the vulnerable Intel Ethernet diagnostics driver (iqvw64.sys, CVE-2015-2291) as the initial loading vector — to terminate endpoint-protection and EDR agent processes directly from kernel space, bypassing driver-signature enforcement and unhooking security sensors before follow-on credential theft (Mandiant; CrowdStrike Falcon detections).
Specific STONESTOP command-line invocation and exact process-targeting logic not publicly documented as of 2026-08-30 — reporting confirms the loader/driver pairing, the certificate-abuse pattern (Section 10), and the CVE-2015-2291 loading vector, but not the operator's precise commands.
Registry-Based Windows Defender Circumvention T1112 / T1562.001
EDR BYPASS reg.exe
A batch script recovered during a Scattered Spider intrusion deletes Windows Defender/Threat-Protection registry policy keys to disable native AV before further tooling is staged. GuidePoint Security notes the command sequence closely mirrors "fix" instructions publicly posted by Microsoft Community forum moderators for unrelated troubleshooting purposes, repurposed here for deliberate defense evasion.
reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies" /f (Source: GuidePoint Security, "Worldwide Web: An Analysis of Tactics and Techniques Attributed to Scattered Spider" — full accompanying script and additional deleted subkeys not fully published as of 2026-08-30.)
AMSI & Antivirus Disabling via Obfuscated Scripts T1562.001 / T1027
EDR BYPASS
Independent of the BYOVD driver path, Halcyon reporting documents the group disabling Windows Defender, SentinelOne, and CrowdStrike Falcon agents through obfuscated scripts that interact directly with underlying system services, and disabling AMSI to permit unimpeded execution of subsequent PowerShell-based tooling.
Specific obfuscation method and exact script content not publicly documented as of 2026-08-30 — Halcyon's reporting confirms the outcome (named products disabled, AMSI bypassed) but not the underlying code.
C2 Blending via Trusted SaaS/PaaS Subdomains T1102 / T1572
NETWORK Chisel · Teleport · trycloudflare.com
Chisel instances deployed on compromised VMware vCenter appliances have been configured to communicate with trycloudflare.com subdomains, and Teleport-based C2 has beaconed to victim-specific hostnames under teleport.sh — in both cases riding infrastructure and TLS certificates belonging to trusted third-party platforms (Cloudflare, Teleport) so the traffic blends with legitimate DevOps/remote-access flows and evades detection rules built around known-bad domains or ASNs (GuidePoint Security; multiple DFIR write-ups). Silent Push separately documents a broader strategic shift toward routing C2 through Microsoft Graph and Outlook APIs, which removes the need for attacker-registered domains or VPS infrastructure that defenders can enumerate and block outright.
Specific Chisel/Teleport configuration flags and Microsoft Graph API call patterns not publicly documented in full as of 2026-08-30.
Network Anomaly Evasion via Residential Proxies & Clean-IP Authentication T1090.002 / T1078.004
NETWORK SIEM EVASION
Authenticating to victim cloud consoles (Entra ID, Okta) from clean, non-VPN U.S. residential IP space rather than commercial VPN or datacenter exit nodes defeats both network-layer geofencing and identity-platform risk-scoring rules that are tuned to flag known-VPN ASNs or improbable-travel patterns — a technique that shifts the detection burden from network indicators onto behavioral/identity analytics that most organizations have not yet operationalized (Team Cymru).
Specific residential-proxy provider(s) used not publicly attributed as of 2026-08-30.
12
Emulation Resources MITRE CTID & Published Adversary Emulation Plans
MITRE CTID — NOT AVAILABLE No Adversary Emulation Plan Published
No MITRE Center for Threat-Informed Defense Full Emulation Plan has been published for Scattered Spider, UNC3944, Octo Tempest, or Muddled Libra as of 2026-08-30 (verified directly against the Adversary Emulation Library's repository listing). The library's current Full Emulation Plans cover APT29, Blind Eagle, Carbanak Group, FIN6, FIN7, menuPass, OceanLotus, OilRig, Sandworm, Turla, and Wizard Spider — no help-desk-vishing-led eCrime/ransomware-affiliate actor from The Com ecosystem is represented at this time.
Additional Emulation Resources
AttackIQ
Security Optimization Platform emulation scenario covering ransomware (BlackCat, DragonForce), stealers (Atomic, Lumma, Vidar, AveMaria, Raccoon), RATs (RattyRAT, SpectreRAT, Sorillus), the STONESTOP/POORTRY BYOVD pair, and tooling for lateral movement (Impacket wmiexec.py), credential theft (Mimikatz, LaZagne, secretsdump.py), and discovery (ADRecon, RustScan, TruffleHog) · Accessed: 2026-08-30
Atomic Red Team
Atomic test, directly applicable — DCSync is a documented Scattered Spider Active Directory credential-access technique (Section 04) · Accessed: 2026-08-30
Atomic Red Team
Atomic test, directly applicable — SSH pivoting into VMware vCenter Server Appliances is a documented lateral-movement technique · Accessed: 2026-08-30
Atomic Red Team
Atomic test using rclone to a remote MEGA/AWS S3 target — directly applicable to the group's documented pre-encryption exfiltration tradecraft · Accessed: 2026-08-30
SigmaHQ
Detection rule for ngrok process execution, a documented Scattered Spider tunneling tool (Section 06) · Accessed: 2026-08-30
SigmaHQ
Detection rule for network connections to ngrok tunnel domains, covering the group's tunneling-based C2 pattern (Section 11) · Accessed: 2026-08-30
13
References URLs are NOT defanged — navigate directly
CISA / FBI
Accessed: 2026-08-29
Krebs on Security
Accessed: 2026-08-29
Krebs on Security
Accessed: 2026-08-29
Acronis TRU
Accessed: 2026-08-29
CYFIRMA
Accessed: 2026-08-29
Cloudskope
Accessed: 2026-08-29
ReliaQuest
Accessed: 2026-08-30
AttackIQ
Accessed: 2026-08-30