| Scattered Spider | |
|---|---|
| 🕷️ Threat actor emblem (illustrative) | |
| Also known as | Octo Tempest · UNC3944 · Starfraud · Muddled Libra · Scatter Swine |
| Formation | c. 2022 |
| Type | Cybercriminal group / Ransomware affiliate |
| Purpose | Financial gain, data extortion |
| Target Sectors | Gaming, Hospitality, IT Services, Telecom |
| Affiliation | ALPHV/BlackCat (Affiliate) |
| Attribution confidence | Moderate/High (Western-based) |
| Status | ● Active |
| Notable incidents | MGM Resorts, Caesars, Okta |
Scattered Spider (internally tracked as UNC3944 by Mandiant and Octo Tempest by Microsoft) is a highly prolific and sophisticated cybercriminal collective known for its mastery of social engineering. Unlike many traditional APTs that rely on technical zero-day exploits, Scattered Spider leverages native English proficiency to manipulate IT help desks and bypass identity-based security controls.[1]
The group gained global notoriety in late 2023 following high-profile attacks on major Las Vegas casino operators, demonstrating a capability to paralyze large-scale physical and digital operations through credential theft and ransomware deployment.[2]
UNC3944 (Mandiant) · Octo Tempest (Microsoft) · Starfraud (Group-IB) · Muddled Libra (Palo Alto Unit 42) · Scatter Swine (Okta) · IABG1015
Overview
Active since at least early 2022, Scattered Spider is composed primarily of young, native English-speaking individuals, likely based in North America and the United Kingdom. The group is characterized by its agility and its focus on Identity-as-a-Service (IDaaS) platforms like Okta and Azure Active Directory. They are frequently observed acting as an affiliate for the ALPHV (BlackCat) ransomware-as-a-service (RaaS) operation.[1]
Origins and “The Com”
Security researchers believe Scattered Spider emerged from a broader ecosystem of cybercriminals known as “The Com.” This loosely organized community specializes in SIM swapping, account takeovers, and social engineering. While many members initially focused on low-level fraud, Scattered Spider represents a professionalized tier of this community that has transitioned into high-stakes corporate extortion.
Targets and Victimology
- Hospitality & Gaming — Large-scale casino resorts and hotel chains.
- Technology & BPO — IT service providers, business process outsourcing firms, and customer support centers.
- Telecommunications — Targeting carriers for SIM swapping and network access.
- Critical Infrastructure — Increasingly targeting logistics and retail sectors to maximize extortion pressure.
Tactics, Techniques, and Procedures
| Tactic | Technique | Description |
|---|---|---|
| Initial Access | Social Engineering | Calling help desks to reset passwords or register new MFA devices by impersonating employees. |
| MFA Bypass | MFA Fatigue/Push Bombing | Bombarding users with push notifications until they approve the login request. | SIM Swapping | Porting employee phone numbers to attacker-controlled SIM cards to intercept SMS codes. |
| Persistence | Identity Provider Access | Modifying Okta or Azure AD settings to maintain access even if passwords are changed. |
Toolset and Software
The group often utilizes “Living off the Land” (LotL) techniques and legitimate remote monitoring and management (RMM) tools to avoid detection by EDR solutions:
- RMM Tools: ScreenConnect, AnyDesk, FleetDeck, and NetSupport Manager.
- Data Exfiltration: Rclone (often masked as legitimate activity).
- Tunneling: Ngrok and Cloudflared for bypassing network security.
- Ransomware: ALPHV/BlackCat, RansomHub (more recently).
Notable Attacks
| Date | Target | Impact |
|---|---|---|
| Aug 2023 | Caesars Entertainment | Reported $15 million ransom payment to prevent data leak. |
| Sep 2023 | MGM Resorts | Widespread operational disruption; booking systems and slot machines disabled for days. |
| Late 2023 | Okta (Indirect) | The group targeted Okta’s support system via a compromised service provider. |
Detection and Mitigation
Defending against Scattered Spider requires a shift toward phishing-resistant MFA (such as FIDO2 security keys) and strict verification protocols for help desk interactions. Monitoring for unusual RMM tool execution and modifications to Identity Provider (IdP) configurations is critical for early detection.
References
- Mandiant, “UNC3944: The Identity-Focused Threat Group” (2023).
- FBI & CISA Cybersecurity Advisory, “Scattered Spider” (AA23-320A).
- Microsoft, “Octo Tempest: A rising financial threat” (2023).
- CrowdStrike Intelligence, “Analysis of Muddled Libra Operations” (2024).
