Threat Actor Unknown origin
Scattered Spider
Also known as: UNC3944 · Muddled Libra · Oktapus · Scattered Swine · Scatter Swine · Octo Tempest · 0ktapus · Storm-0971 · DEV-0971 · Starfraud
Scattered Spider, a highly active hacking group, has made headlines by targeting more than 130 organizations, with the number of victims steadily increasing.
Indicators of Compromise 9
MITRE ATT&CK TTPs 136
T1003 T1005 T1021 T1021.001 T1021.002 T1021.003 T1021.004 T1021.005 T1021.006 T1021.007 T1021.008 T1021.009 T1021.010 T1021.011 T1021.012 T1021.013 T1021.014 T1021.015 T1021.016 T1021.017 T1021.018 T1021.019 T1021.020 T1021.021 T1021.022 T1021.023 T1021.024 T1021.025 T1021.026 T1021.027 T1021.028 T1021.029 T1021.030 T1021.031 T1021.032 T1021.033 T1021.034 T1021.035 T1021.036 T1021.037 T1021.038 T1021.039 T1021.040 T1021.041 T1021.042 T1021.043 T1021.044 T1021.045 T1021.046 T1021.047 T1021.048 T1021.049 T1021.050 T1021.051 T1021.052 T1021.053 T1021.054 T1021.055 T1021.056 T1021.057 T1021.058 T1021.059 T1021.060 T1021.061 T1021.062 T1021.063 T1021.064 T1021.065 T1021.066 T1021.067 T1021.068 T1021.069 T1021.070 T1021.071 T1021.072 T1021.073 T1021.074 T1021.075 T1021.076 T1021.077 T1021.078 T1021.079 T1021.080 T1021.081 T1021.082 T1021.083 T1021.084 T1021.085 T1021.086 T1021.087 T1021.088 T1021.089 T1021.090 T1021.091 T1021.092 T1021.093 T1021.094 T1021.095 T1021.096 T1021.097 T1021.098 T1021.099 T1021.100 T1027 T1027.002 T1048 T1053.005 T1055 T1055.012 T1056.001 T1059.001 T1059.005 T1070.004 T1071 T1071.001 T1071.002 T1071.003 T1071.004 T1078 T1082 T1085 T1090 T1095 T1102 T1105 T1114.001 T1133 T1202 T1484.001 T1484.002 T1489 T1496 T1548 T1558.003 T1566 T1566.002
OS Credential Dumping
Credential Access
Data from Local System
Collection
Remote Services
Lateral Movement
Remote Desktop Protocol
Lateral Movement
SMB/Windows Admin Shares
Lateral Movement
Distributed Component Object Model
Lateral Movement
SSH
Lateral Movement
VNC
Lateral Movement
Windows Remote Management
Lateral Movement
Cloud Services
Lateral Movement
Direct Cloud VM Connections
Lateral Movement
T1021.009
T1021.010
T1021.011
T1021.012
T1021.013
T1021.014
T1021.015
T1021.016
T1021.017
T1021.018
T1021.019
T1021.020
T1021.021
T1021.022
T1021.023
T1021.024
T1021.025
T1021.026
T1021.027
T1021.028
T1021.029
T1021.030
T1021.031
T1021.032
T1021.033
T1021.034
T1021.035
T1021.036
T1021.037
T1021.038
T1021.039
T1021.040
T1021.041
T1021.042
T1021.043
T1021.044
T1021.045
T1021.046
T1021.047
T1021.048
T1021.049
T1021.050
T1021.051
T1021.052
T1021.053
T1021.054
T1021.055
T1021.056
T1021.057
T1021.058
T1021.059
T1021.060
T1021.061
T1021.062
T1021.063
T1021.064
T1021.065
T1021.066
T1021.067
T1021.068
T1021.069
T1021.070
T1021.071
T1021.072
T1021.073
T1021.074
T1021.075
T1021.076
T1021.077
T1021.078
T1021.079
T1021.080
T1021.081
T1021.082
T1021.083
T1021.084
T1021.085
T1021.086
T1021.087
T1021.088
T1021.089
T1021.090
T1021.091
T1021.092
T1021.093
T1021.094
T1021.095
T1021.096
T1021.097
T1021.098
T1021.099
T1021.100
Obfuscated Files or Information
Defense Evasion
Software Packing
Defense Evasion
Exfiltration Over Alternative Protocol
Exfiltration
Scheduled Task
Execution
Process Injection
Defense Evasion
Process Hollowing
Defense Evasion
Keylogging
Collection
PowerShell
Execution
Visual Basic
Execution
File Deletion
Defense Evasion
Application Layer Protocol
Command And Control
Web Protocols
Command And Control
File Transfer Protocols
Command And Control
Mail Protocols
Command And Control
DNS
Command And Control
Valid Accounts
Defense Evasion
System Information Discovery
Discovery
T1085
Proxy
Command And Control
Non-Application Layer Protocol
Command And Control
Web Service
Command And Control
Ingress Tool Transfer
Command And Control
Local Email Collection
Collection
External Remote Services
Persistence
Indirect Command Execution
Defense Evasion
Group Policy Modification
Defense Evasion
Trust Modification
Defense Evasion
Service Stop
Impact
Resource Hijacking
Impact
Abuse Elevation Control Mechanism
Privilege Escalation
Kerberoasting
Credential Access
Phishing
Initial Access
Spearphishing Link
Initial Access
Source Articles
Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack
Owen Flowers and Thalha Jubair, alleged members of the Scattered Spider threat actor group, were sentenced to five and a half years each for their roles in a 2024 cyberattack on Transport for London (TfL) that disrupted 148 systems and affected 27,000 employees. The attack, which exfiltrated personal and financial data and nearly led to a network shutdown, caused £29 million in losses and recovery costs. The hackers also targeted US healthcare organizations, with threats to disrupt critical systems, and are linked to a broader campaign of social engineering, SIM swapping, and data extortion spanning hundreds of attacks from 2022 to 2025.
hacker-news ·4w ago
Scattered Spider members behind TfL hack get five years in prison
Two key members of the Scattered Spider cybercrime group, Thalha Jubair and Owen Flowers, were sentenced to five years and six months in prison for their involvement in the August 2024 breach of Transport for London (TfL). The attack disrupted critical internal systems, forced 27,000 employees to reset passwords, and led to the theft of customer data. The group is also linked to over 120 network intrusions globally, including attacks on U.S. healthcare providers and critical infrastructure, resulting in over $115 million in extortions.
bleeping-computer ·4w ago
Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access
A threat actor tracked as O-UNC-066 is conducting vishing attacks to trick Microsoft 365 users into enrolling attacker-controlled passkeys through a phishing kit that mimics the legitimate Microsoft Entra passkey enrollment process. The attackers register domains with 'passkey' in the name and use voice calls to socially engineer victims into following a fake enrollment flow, ultimately granting unauthorized access to their accounts. The phishing kit is operator-controlled and adapts in real time to the victim's MFA method, allowing the attacker to capture credentials and approve passkey registration. This campaign targets multiple industries and abuses Microsoft's passkey adoption initiative as a social engineering lure.
hacker-news ·1mo ago
ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories
This week's threat landscape highlights a range of cyber activities, from cloud bucket hijacking and ransomware tooling overlaps to social engineering campaigns and supply chain attacks. Notable incidents include a global fraud operation resulting in nearly 6,000 arrests, typosquatting of payment SDKs on npm and PyPI, and the abuse of Microsoft Teams for delivering EtherRAT. Additionally, new techniques like Process Parameter Poisoning and ADFS token forgery underscore evolving evasion and privilege escalation methods.
hacker-news ·1mo ago
Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker
U.S. prosecutors have linked 19-year-old Peter Stokes, allegedly part of the Scattered Spider hacking group, to a May 2025 breach of a luxury jewelry retailer. The attackers used social engineering to manipulate the IT help desk into resetting passwords and bypassing multifactor authentication, then deployed tunneling tools like ngrok and Teleport to exfiltrate over 77 GB of data. Despite ransomware deployment being blocked, the attackers demanded $8 million in cryptocurrency. The FBI traced Stokes via a persistent Windows device ID tied to Microsoft account activity and correlated IP addresses from his online accounts.
hacker-news ·1mo ago
⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More
The article covers multiple cyber threats including the disruption of the NetNut residential proxy network, which leveraged compromised home devices to route malicious traffic. Threat actors are targeting researchers with fake proof-of-concept repositories delivering the ChocoPoC RAT, while the Scattered Spider group is linked to extortion attempts. New malware such as Ousaban and browser-based ransomware exploit social engineering and legitimate browser APIs, and AI-driven attacks are increasing in sophistication, including indirect prompt injection and fake phishing pages generated via AI.
hacker-news ·1mo ago
Inside the Modern SOC: The 72-Minute Race
The article highlights the increasing speed of cyberattacks, with adversaries achieving data exfiltration in as little as 72 minutes. Attackers leverage compromised credentials and identity-based techniques to rapidly escalate privileges and move laterally across environments. Modern SOCs struggle to keep pace due to manual processes and fragmented workflows. Threat actors like Muddled Libra and Spoiled Scorpius are exemplifying this trend by exploiting identity weaknesses to accelerate attack timelines.
unit42 ·2mo ago