Scattered Spider is a financially motivated, loosely affiliated eCrime collective active since at least May 2022, tracked across the industry under a sprawling list of aliases — UNC3944 (Mandiant/Google), Octo Tempest (Microsoft), Muddled Libra (Unit 42), Roasted 0ktapus and Scatter Swine (CrowdStrike and others) — and catalogued by MITRE ATT&CK as G1015. Rather than relying primarily on malware or novel exploits, the group has built one of the most effective social-engineering operations in modern cybercrime: impersonating employees and IT help-desk staff by phone (vishing) to trigger password and multi-factor-authentication (MFA) resets, bypassing identity controls that stop most purely technical intrusions.
The group's target list has expanded relentlessly since its 2022 origins in telecom-focused SIM-swapping: financial-services firms in late 2023, food-services and hospitality organizations by mid-2024, UK retailers — Marks & Spencer, Co-op, Harrods — in spring 2025, U.S. insurance carriers including Aflac in mid-2025, and the aviation sector — Qantas, Hawaiian Airlines, WestJet — in mid-2025. Each wave follows a similar pattern: concentrated targeting of a single vertical for several weeks before pivoting to the next, suggesting centralized target-selection despite the group's decentralized membership.
Scattered Spider is best understood as a persistent capability within a much larger cybercriminal ecosystem known as "The Com" — an English-speaking, largely Discord/Telegram-coordinated community of young hackers spanning the US, UK, and Canada that also produced LAPSUS$ and shares members, tooling, and tradecraft across brands (see companion profile: LAPSUS$). Since 2023 the group has operated as a flexible ransomware affiliate — deploying ALPHV/BlackCat, then RansomHub and Qilin, and by 2025 DragonForce — rather than building or maintaining its own leak infrastructure, and in 2025–2026 elements of Scattered Spider merged branding with LAPSUS$ and ShinyHunters under the "Scattered LAPSUS$ Hunters" umbrella.
The group matters now because arrests have proven only partially disruptive. U.S. and U.K. law enforcement charged and sentenced several alleged members through 2025 and into 2026, including a UK member linked to over 120 intrusions and $115M+ in ransom payments, yet the collective's loose, brand-fluid structure and deep bench within The Com have allowed activity to continue and even escalate — most notably a strategic pivot toward hijacking VMware ESXi/vSphere infrastructure to deploy ransomware directly from the hypervisor layer, a technique that bypasses most endpoint security entirely.
Attribution to a loosely organized collective of primarily young, native-English-speaking individuals based in the US, UK, and Canada is HIGH, supported by multiple independent law-enforcement actions (UK NCA/police, US DOJ/FBI) resulting in named arrests, guilty pleas, and sentencing tied to specific intrusions. However, "Scattered Spider" functions more as a shared tradecraft brand within The Com than a fixed membership roster — individual campaigns may involve different, overlapping sets of operators, and clean separation from affiliated brands (LAPSUS$, ShinyHunters, individual DragonForce affiliates) is not always possible.
Scattered Spider's defining characteristic is that nearly its entire intrusion lifecycle can run through social engineering rather than malware. Initial access typically begins with reconnaissance on LinkedIn, breach-data marketplaces, and general OSINT to build a convincing profile of a real employee, followed by a phone call to the target organization's (or its MSP's) IT help desk in which an operator — often a native English speaker capable of mimicking regional accents — impersonates that employee to request a password reset or MFA re-enrollment (T1566.004, T1598.004, T1684.001). Where a live call is impractical, the group substitutes SMS phishing or fake corporate-login domains engineered to closely mirror the real single sign-on portal (T1583.001, T1598.003).
Once inside, the group avoids traditional malware wherever possible, instead abusing legitimate administrative tools and cloud consoles already present in the environment: registering its own MFA device to a compromised account (T1556.006), enumerating Active Directory and Azure AD/Entra ID via PowerShell and native tooling (T1087, T1069), and establishing remote access through commercial tools like TeamViewer, AnyDesk, and ngrok, or tunneling utilities such as Chisel and Teleport (T1219, T1572). Credential harvesting relies on tools like Mimikatz, LaZagne, and Raccoon Stealer, and where legitimate access alone is insufficient, the group has exploited specific vulnerabilities — CVE-2021-35464 in ForgeRock OpenAM, and a vulnerable-driver exploit chain (CVE-2015-2291) — for privilege escalation and EDR evasion.
Since 2024–2025, the group's most consequential evolution has been a pivot toward VMware vSphere/ESXi environments: after gaining Active Directory dominance, operators enumerate vCenter and ESXi hosts, deploy tools like RustScan and Impacket for lateral movement, and ultimately push ransomware — historically ALPHV/BlackCat, and by 2025, DragonForce — directly onto the hypervisor layer, encrypting virtual-machine datastores in bulk while bypassing guest-OS endpoint security almost entirely. Data exfiltration typically precedes encryption, using legitimate cloud-storage and transfer services (MEGA, Snowflake, AWS S3, Rclone) to support double extortion, and the group frequently harasses victim executives, employees, and even incident responders directly by phone and social media during negotiations — a psychological-pressure tactic distinct from most ransomware operators.
| Type | Value / Description | Source | Date |
|---|---|---|---|
| CVE | CVE-2021-35464 — ForgeRock OpenAM remote code execution, used for initial access against telecom victims | CISA AA23-320A | 2023-11-16 |
| CVE | CVE-2024-37085 — VMware ESXi authentication-bypass, exploited to deploy rootkits and disable EDR | Google Cloud / Security Affairs | 2025-07 |
| MALWARE | DragonForce ransomware paired with BYOVD drivers truesight[.]sys and rentdrv2[.]sys to terminate security processes | Acronis TRU | 2025 |
| TOOL | ngrok, Chisel, Teleport, AnyDesk, TeamViewer used as dual-use C2/tunneling tools — flag by anomalous behavior, not by static signature | MITRE ATT&CK G1015 | 2022–2026 |
| NOTE | No durable static IP/domain indicator list exists for this actor: Scattered Spider rotates lookalike SSO/login domains per engagement and relies heavily on legitimate/dual-use services (MEGA, Snowflake, AWS S3) rather than fixed C2 infrastructure. Defenders should prioritize the behavioral and identity-based indicators in Sections 04 and 06 over static IOCs, and consult CISA AA23-320A and current vendor threat-intel feeds for the latest domain patterns. | ||
Scattered Spider represents a category of risk that most enterprise security programs are not built to counter: a well-resourced, financially motivated adversary whose primary attack surface is human trust in IT support processes rather than software vulnerabilities. Arrests have demonstrably disrupted specific individuals — the September 2025 charges against Thalha Jubair and Owen Flowers, and their subsequent guilty pleas and sentencing, removed operators tied to a documented $115M+ in extortion payments — but have not visibly slowed the broader brand's operational tempo, which continued through the 2025 aviation and insurance waves and into the 2026 "Scattered LAPSUS$ Hunters" resurgence.
The group's pivot to VMware ESXi/vSphere as a direct ransomware deployment surface is the most significant recent capability shift: it converts a single compromised set of AD-domain-admin-equivalent credentials into the ability to encrypt an entire virtualized estate at once, sidestepping guest-OS endpoint detection almost entirely. Combined with the group's established willingness to harass victims and responders directly during negotiations, this makes Scattered Spider incidents unusually fast-moving and organizationally disruptive compared to a typical ransomware-affiliate intrusion.
Competing hypotheses persist about how tightly "Scattered Spider," "LAPSUS$," and "ShinyHunters" should be treated as one entity versus three overlapping-but-distinct brands sharing a talent pool within The Com; this profile treats them as a shared ecosystem rather than a single organization, consistent with vendor practice (Google/Mandiant, Microsoft, and CrowdStrike each retain separate tracking designations). Confidence in the near-term trajectory would increase with corroborated evidence that the claimed ShinySp1d3r RaaS platform has reached operational status, and would decrease if 2026 law-enforcement actions beyond Jubair and Flowers meaningfully reduce the pool of experienced vishing operators — the group's actual scarce resource, given how replicable its non-malware tradecraft otherwise is.