news.mlab.sh
Threat intelligence
Threat actor

Scattered Spider

Profile from actors.mlab.sh, coverage from our own index.

TLP
WHITE

An affiliate group of ALPHV, BlackCat Gang (Mandiant) UNC3944 is a financially motivated threat cluster that has persistently used phone-based social engineering and SMS phishing campaigns (smishing) to obtain credentials to gain and escalate access to victim organizations. At least some UNC3944 threat actors appear to operate in underground communities, such as Telegram and underground forums, which they may leverage to acquire tools, services, and/or other support to augment their operations. This activity overlaps with activity that has been reported in open sources as '0ktapus,' 'Scatter Swine,' and 'Scattered Spider.' Since 2022 and through early 2023, UNC3944 appeared to focus on accessing credentials or systems used to enable SIM swapping attacks, likely in support of secondary criminal operations occurring outside of victim environments. However, in mid-2023, UNC3944 began to shift to deploying ransomware in victim environments, signaling an expansion in the group's monetization strategies. These changes in their end goals signal that the industries targeted by UNC3944 will continue to expand; Mandiant has already directly observed their targeting broaden beyond telecommunication and business process outsourcer (BPO) companies to a wide range of industries including hospitality, retail, media and entertainment, and financial services. Around July 2025, ShinyHunters teamed up or merged with Scattered Spider. They share their Telegram channel also with Lapsus$, so they may all work together now – see the DataBreaches.net references in the Information section under ShinyHunters.

Also known as

0ktapusLUCR-3Muddled LibraOcto TempestRoasted 0ktapusScatter SwineScattered SpiderStar FraudStorm-0875UNC3944

Vulnerabilities exploited

Tooling and malware

BlackCatRaccoon StealerWarzoneRATConnectWiseLaZagneMimikatzngrokRcloneTor

MITRE ATT&CK techniques

T1074 Data StagedT1114 Email CollectionT1530 Data from Cloud StorageT1090 ProxyT1105 Ingress Tool TransferT1572 Protocol TunnelingT1539 Steal Web Session CookieT1621 Multi-Factor Authentication Request GenerationT1685 Disable or Modify ToolsT1016 System Network Configuration DiscoveryT1018 Remote System DiscoveryT1069 Permission Groups DiscoveryT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1087 Account DiscoveryT1217 Browser Information DiscoveryT1538 Cloud Service DashboardT1580 Cloud Infrastructure DiscoveryT1204 User ExecutionT1041 Exfiltration Over C2 ChannelT1486 Data Encrypted for ImpactT1490 Inhibit System RecoveryT1657 Financial TheftT1098 Account ManipulationT1133 External Remote ServicesT1136 Create AccountT1068 Exploitation for Privilege EscalationT1589 Gather Victim Identity InformationT1598 Phishing for InformationT1006 Direct Volume AccessT1078 Valid Accounts

Coverage 25