Threat Actor Unknown origin

Scattered Spider

Also known as: UNC3944 · Muddled Libra · Oktapus · Scattered Swine · Scatter Swine · Octo Tempest · 0ktapus · Storm-0971 · DEV-0971 · Starfraud

Scattered Spider, a highly active hacking group, has made headlines by targeting more than 130 organizations, with the number of victims steadily increasing.

Indicators of Compromise 9

MITRE ATT&CK TTPs 136

T1003
OS Credential Dumping
Credential Access
T1005
Data from Local System
Collection
T1021
Remote Services
Lateral Movement
T1021.001
Remote Desktop Protocol
Lateral Movement
T1021.002
SMB/Windows Admin Shares
Lateral Movement
T1021.003
Distributed Component Object Model
Lateral Movement
T1021.004
SSH
Lateral Movement
T1021.005
VNC
Lateral Movement
T1021.006
Windows Remote Management
Lateral Movement
T1021.007
Cloud Services
Lateral Movement
T1021.008
Direct Cloud VM Connections
Lateral Movement
T1021.009
T1021.009
T1021.010
T1021.010
T1021.011
T1021.011
T1021.012
T1021.012
T1021.013
T1021.013
T1021.014
T1021.014
T1021.015
T1021.015
T1021.016
T1021.016
T1021.017
T1021.017
T1021.018
T1021.018
T1021.019
T1021.019
T1021.020
T1021.020
T1021.021
T1021.021
T1021.022
T1021.022
T1021.023
T1021.023
T1021.024
T1021.024
T1021.025
T1021.025
T1021.026
T1021.026
T1021.027
T1021.027
T1021.028
T1021.028
T1021.029
T1021.029
T1021.030
T1021.030
T1021.031
T1021.031
T1021.032
T1021.032
T1021.033
T1021.033
T1021.034
T1021.034
T1021.035
T1021.035
T1021.036
T1021.036
T1021.037
T1021.037
T1021.038
T1021.038
T1021.039
T1021.039
T1021.040
T1021.040
T1021.041
T1021.041
T1021.042
T1021.042
T1021.043
T1021.043
T1021.044
T1021.044
T1021.045
T1021.045
T1021.046
T1021.046
T1021.047
T1021.047
T1021.048
T1021.048
T1021.049
T1021.049
T1021.050
T1021.050
T1021.051
T1021.051
T1021.052
T1021.052
T1021.053
T1021.053
T1021.054
T1021.054
T1021.055
T1021.055
T1021.056
T1021.056
T1021.057
T1021.057
T1021.058
T1021.058
T1021.059
T1021.059
T1021.060
T1021.060
T1021.061
T1021.061
T1021.062
T1021.062
T1021.063
T1021.063
T1021.064
T1021.064
T1021.065
T1021.065
T1021.066
T1021.066
T1021.067
T1021.067
T1021.068
T1021.068
T1021.069
T1021.069
T1021.070
T1021.070
T1021.071
T1021.071
T1021.072
T1021.072
T1021.073
T1021.073
T1021.074
T1021.074
T1021.075
T1021.075
T1021.076
T1021.076
T1021.077
T1021.077
T1021.078
T1021.078
T1021.079
T1021.079
T1021.080
T1021.080
T1021.081
T1021.081
T1021.082
T1021.082
T1021.083
T1021.083
T1021.084
T1021.084
T1021.085
T1021.085
T1021.086
T1021.086
T1021.087
T1021.087
T1021.088
T1021.088
T1021.089
T1021.089
T1021.090
T1021.090
T1021.091
T1021.091
T1021.092
T1021.092
T1021.093
T1021.093
T1021.094
T1021.094
T1021.095
T1021.095
T1021.096
T1021.096
T1021.097
T1021.097
T1021.098
T1021.098
T1021.099
T1021.099
T1021.100
T1021.100
T1027
Obfuscated Files or Information
Defense Evasion
T1027.002
Software Packing
Defense Evasion
T1048
Exfiltration Over Alternative Protocol
Exfiltration
T1053.005
Scheduled Task
Execution
T1055
Process Injection
Defense Evasion
T1055.012
Process Hollowing
Defense Evasion
T1056.001
Keylogging
Collection
T1059.001
PowerShell
Execution
T1059.005
Visual Basic
Execution
T1070.004
File Deletion
Defense Evasion
T1071
Application Layer Protocol
Command And Control
T1071.001
Web Protocols
Command And Control
T1071.002
File Transfer Protocols
Command And Control
T1071.003
Mail Protocols
Command And Control
T1071.004
DNS
Command And Control
T1078
Valid Accounts
Defense Evasion
T1082
System Information Discovery
Discovery
T1085
T1085
T1090
Proxy
Command And Control
T1095
Non-Application Layer Protocol
Command And Control
T1102
Web Service
Command And Control
T1105
Ingress Tool Transfer
Command And Control
T1114.001
Local Email Collection
Collection
T1133
External Remote Services
Persistence
T1202
Indirect Command Execution
Defense Evasion
T1484.001
Group Policy Modification
Defense Evasion
T1484.002
Trust Modification
Defense Evasion
T1489
Service Stop
Impact
T1496
Resource Hijacking
Impact
T1548
Abuse Elevation Control Mechanism
Privilege Escalation
T1558.003
Kerberoasting
Credential Access
T1566
Phishing
Initial Access
T1566.002
Spearphishing Link
Initial Access

Source Articles

Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack
Owen Flowers and Thalha Jubair, alleged members of the Scattered Spider threat actor group, were sentenced to five and a half years each for their roles in a 2024 cyberattack on Transport for London (TfL) that disrupted 148 systems and affected 27,000 employees. The attack, which exfiltrated personal and financial data and nearly led to a network shutdown, caused £29 million in losses and recovery costs. The hackers also targeted US healthcare organizations, with threats to disrupt critical systems, and are linked to a broader campaign of social engineering, SIM swapping, and data extortion spanning hundreds of attacks from 2022 to 2025.
hacker-news ·4w ago
Scattered Spider members behind TfL hack get five years in prison
Two key members of the Scattered Spider cybercrime group, Thalha Jubair and Owen Flowers, were sentenced to five years and six months in prison for their involvement in the August 2024 breach of Transport for London (TfL). The attack disrupted critical internal systems, forced 27,000 employees to reset passwords, and led to the theft of customer data. The group is also linked to over 120 network intrusions globally, including attacks on U.S. healthcare providers and critical infrastructure, resulting in over $115 million in extortions.
bleeping-computer ·4w ago
Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access
A threat actor tracked as O-UNC-066 is conducting vishing attacks to trick Microsoft 365 users into enrolling attacker-controlled passkeys through a phishing kit that mimics the legitimate Microsoft Entra passkey enrollment process. The attackers register domains with 'passkey' in the name and use voice calls to socially engineer victims into following a fake enrollment flow, ultimately granting unauthorized access to their accounts. The phishing kit is operator-controlled and adapts in real time to the victim's MFA method, allowing the attacker to capture credentials and approve passkey registration. This campaign targets multiple industries and abuses Microsoft's passkey adoption initiative as a social engineering lure.
hacker-news ·1mo ago
ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories
This week's threat landscape highlights a range of cyber activities, from cloud bucket hijacking and ransomware tooling overlaps to social engineering campaigns and supply chain attacks. Notable incidents include a global fraud operation resulting in nearly 6,000 arrests, typosquatting of payment SDKs on npm and PyPI, and the abuse of Microsoft Teams for delivering EtherRAT. Additionally, new techniques like Process Parameter Poisoning and ADFS token forgery underscore evolving evasion and privilege escalation methods.
hacker-news ·1mo ago
Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker
U.S. prosecutors have linked 19-year-old Peter Stokes, allegedly part of the Scattered Spider hacking group, to a May 2025 breach of a luxury jewelry retailer. The attackers used social engineering to manipulate the IT help desk into resetting passwords and bypassing multifactor authentication, then deployed tunneling tools like ngrok and Teleport to exfiltrate over 77 GB of data. Despite ransomware deployment being blocked, the attackers demanded $8 million in cryptocurrency. The FBI traced Stokes via a persistent Windows device ID tied to Microsoft account activity and correlated IP addresses from his online accounts.
hacker-news ·1mo ago
⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More
The article covers multiple cyber threats including the disruption of the NetNut residential proxy network, which leveraged compromised home devices to route malicious traffic. Threat actors are targeting researchers with fake proof-of-concept repositories delivering the ChocoPoC RAT, while the Scattered Spider group is linked to extortion attempts. New malware such as Ousaban and browser-based ransomware exploit social engineering and legitimate browser APIs, and AI-driven attacks are increasing in sophistication, including indirect prompt injection and fake phishing pages generated via AI.
hacker-news ·1mo ago
Inside the Modern SOC: The 72-Minute Race
The article highlights the increasing speed of cyberattacks, with adversaries achieving data exfiltration in as little as 72 minutes. Attackers leverage compromised credentials and identity-based techniques to rapidly escalate privileges and move laterally across environments. Modern SOCs struggle to keep pace due to manual processes and fragmented workflows. Threat actors like Muddled Libra and Spoiled Scorpius are exemplifying this trend by exploiting identity weaknesses to accelerate attack timelines.
unit42 ·2mo ago