{
  "name": "Adversary Atlas API",
  "version": "1.0.0",
  "description": "Read-only JSON API over the Adversary Atlas threat actor dataset. Statically generated at build time; no authentication, no rate limits.",
  "generated": "2026-07-31T01:06:07.226Z",
  "datasetCurrentAsOf": "2025-09-01",
  "license": "Data compiled from public primary sources; see /methodology/ for sourcing.",
  "actor": {
    "id": "scattered-spider",
    "slug": "scattered-spider",
    "name": "Scattered Spider",
    "shortName": "Scattered Spider",
    "country": "Multiple / Non-state",
    "countryCode": "XX",
    "sponsorship": "criminal",
    "status": "active",
    "activeSince": "2022",
    "prominence": 92,
    "mitreGroupId": "G1015",
    "tagline": "Native English-speaking teenagers who talk their way past help desks. No exploits, no zero-days — just a convincing phone call.",
    "bio": "Scattered Spider inverted the assumptions most enterprise security programmes are built on.\n\nThe group is composed largely of young, native English-speaking members based in the U.S. and U.K., loosely organised through the online community researchers call \"the Com.\" That demographic detail is operationally decisive: the single most effective control against social engineering has historically been that the caller sounds foreign, reads from a script, and misuses idiom. Scattered Spider callers sound like colleagues, because they are culturally native to the organisations they target.\n\nThe core technique is a phone call to the IT help desk. The caller impersonates an employee — armed with real details harvested from LinkedIn and prior breaches — and asks for an MFA reset or a new device enrolment. Help desks exist to unblock people, are measured on resolution time, and are staffed by people whose job is to be helpful. The group has repeatedly obtained privileged access this way without a single exploit.\n\nWhere phone calls fail, it uses MFA fatigue (repeated push notifications until the target approves one), SIM swapping to intercept SMS codes, and adversary-in-the-middle phishing kits.\n\nIts September 2023 attacks on MGM Resorts and Caesars Entertainment brought the model to public attention: MGM disclosed roughly $100 million in impact, with hotel systems, slot machines, and digital keys disabled for days; Caesars reportedly paid a ransom of about $15 million. The group has since worked with successive ransomware-as-a-service brands — ALPHV/BlackCat, then RansomHub, then DragonForce — and expanded into insurance, retail, and aviation.\n\nSeveral members have been arrested and charged in the U.S. and U.K. Activity attributed to the broader community has continued regardless — the structure is a loose social network, not an organisation with a leadership to decapitate.",
    "attribution": {
      "sponsor": "None — financially motivated criminal group",
      "service": "Loosely organised, primarily U.S. and U.K. based members",
      "confidence": "confirmed",
      "summary": "A financially motivated criminal group with no state sponsorship. Multiple members have been arrested and charged: the U.S. Department of Justice charged five individuals in November 2024 over a phishing campaign against employees at companies nationwide, and further arrests have been made in the U.K. Members are largely young, native English speakers organised through online communities rather than a formal hierarchy, which has allowed attributed activity to continue after arrests.",
      "sources": [
        {
          "org": "U.S. Department of Justice",
          "title": "Five Alleged Members of Scattered Spider Charged with Wire Fraud Conspiracy",
          "url": "https://www.justice.gov/usao-cdca/pr/five-alleged-members-scattered-spider-charged-multi-year-phishing-scheme-steal",
          "date": "2024-11-20"
        },
        {
          "org": "CISA / FBI",
          "title": "Scattered Spider (AA23-320A)",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a",
          "date": "2023-11-16"
        }
      ]
    },
    "motivations": [
      "financial-gain"
    ],
    "targetSectors": [
      "Retail & Hospitality",
      "Financial Services",
      "Telecommunications",
      "Technology",
      "Gaming",
      "Healthcare",
      "Transportation",
      "Managed Service Providers",
      "Legal",
      "Manufacturing"
    ],
    "targetCountries": [
      "United States",
      "United Kingdom",
      "Canada",
      "Australia",
      "Singapore"
    ],
    "aliases": [
      {
        "org": "mitre",
        "name": "Scattered Spider",
        "url": "https://attack.mitre.org/groups/G1015/",
        "correlation": "exact"
      },
      {
        "org": "microsoft",
        "name": "Octo Tempest",
        "correlation": "exact"
      },
      {
        "org": "crowdstrike",
        "name": "Scattered Spider",
        "correlation": "exact"
      },
      {
        "org": "mandiant",
        "name": "UNC3944",
        "correlation": "exact"
      },
      {
        "org": "unit42",
        "name": "Muddled Libra",
        "correlation": "exact"
      },
      {
        "org": "cisa",
        "name": "Scattered Spider",
        "correlation": "exact"
      },
      {
        "org": "trendmicro",
        "name": "Water Curupira",
        "correlation": "partial",
        "note": "Partial overlap with tracked activity"
      },
      {
        "org": "secureworks",
        "name": "GOLD HARVESTER",
        "correlation": "exact"
      },
      {
        "org": "redcanary",
        "name": "Scattered Spider",
        "correlation": "exact",
        "note": "Extensively covered in Red Canary detection research"
      },
      {
        "org": "recordedfuture",
        "name": "Scattered Spider",
        "correlation": "exact"
      }
    ],
    "tools": [
      {
        "name": "Help desk social engineering",
        "type": "lotl",
        "custom": false,
        "description": "The primary access vector — phone calls to IT support requesting MFA resets, made credible by native-speaker fluency and harvested personal detail."
      },
      {
        "name": "MFA fatigue",
        "type": "lotl",
        "custom": false,
        "description": "Repeated authentication push notifications until the target approves one out of confusion or exhaustion."
      },
      {
        "name": "SIM swapping",
        "type": "lotl",
        "custom": false,
        "description": "Carrier social engineering to port a target's number and intercept SMS-based authentication codes."
      },
      {
        "name": "Evilginx / AiTM kits",
        "type": "framework",
        "custom": false,
        "description": "Real-time credential proxies capturing session tokens to bypass MFA."
      },
      {
        "name": "Legitimate RMM tools",
        "type": "utility",
        "custom": false,
        "description": "AnyDesk, TeamViewer, Splashtop, and ScreenConnect installed for persistent access — signed, allowed, and unremarkable."
      },
      {
        "name": "ALPHV / RansomHub / DragonForce",
        "type": "ransomware",
        "custom": false,
        "description": "Successive ransomware-as-a-service brands used as the monetisation layer; the group supplies access and negotiation, not encryption."
      },
      {
        "name": "Vishing and smishing",
        "type": "lotl",
        "custom": false,
        "description": "Voice and SMS phishing impersonating IT support, directing targets to credential harvesting pages."
      }
    ],
    "techniques": [
      {
        "tCode": "T1598.004",
        "name": "Phishing for Information: Spearphishing Voice",
        "tactic": "Reconnaissance",
        "note": "The group's signature — direct phone calls to help desks and employees"
      },
      {
        "tCode": "T1656",
        "name": "Impersonation",
        "tactic": "Defense Evasion",
        "note": "Impersonating employees to IT support, and IT support to employees"
      },
      {
        "tCode": "T1621",
        "name": "Multi-Factor Authentication Request Generation",
        "tactic": "Credential Access",
        "note": "MFA fatigue push bombing"
      },
      {
        "tCode": "T1451",
        "name": "SIM Card Swap",
        "tactic": "Credential Access"
      },
      {
        "tCode": "T1557",
        "name": "Adversary-in-the-Middle",
        "tactic": "Credential Access"
      },
      {
        "tCode": "T1078.004",
        "name": "Valid Accounts: Cloud Accounts",
        "tactic": "Initial Access"
      },
      {
        "tCode": "T1219",
        "name": "Remote Access Software",
        "tactic": "Command and Control",
        "note": "Legitimate commercial RMM tools installed as durable access"
      },
      {
        "tCode": "T1486",
        "name": "Data Encrypted for Impact",
        "tactic": "Impact",
        "note": "Ransomware supplied by affiliated RaaS operations"
      },
      {
        "tCode": "T1567.002",
        "name": "Exfiltration Over Web Service: Exfiltration to Cloud Storage",
        "tactic": "Exfiltration"
      },
      {
        "tCode": "T1531",
        "name": "Account Access Removal",
        "tactic": "Impact",
        "note": "Locking out administrators and disabling recovery paths during an intrusion"
      },
      {
        "tCode": "T1098.005",
        "name": "Account Manipulation: Device Registration",
        "tactic": "Persistence",
        "note": "Enrolling attacker-controlled devices for MFA"
      },
      {
        "tCode": "T1213.003",
        "name": "Data from Information Repositories: Code Repositories",
        "tactic": "Collection"
      }
    ],
    "cves": [
      {
        "cveId": "CVE-2015-2291",
        "firstExploited": "2023-05-01",
        "usage": "A vulnerable signed Intel Ethernet diagnostics driver loaded to terminate EDR processes from kernel space — bring-your-own-vulnerable-driver in place of exploit development.",
        "source": {
          "org": "CrowdStrike",
          "title": "SCATTERED SPIDER Exploits Windows Security Deficiencies with Bring-Your-Own-Vulnerable-Driver Tactic",
          "url": "https://www.crowdstrike.com/blog/scattered-spider-attempts-to-avoid-detection-with-bring-your-own-vulnerable-driver-tactic/",
          "date": "2023-01-10"
        }
      },
      {
        "cveId": "CVE-2024-1709",
        "firstExploited": "2024-02-01",
        "usage": "ConnectWise ScreenConnect authentication bypass exploited for access to managed environments.",
        "source": {
          "org": "CISA / FBI",
          "title": "Scattered Spider advisory update (AA23-320A)",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a",
          "date": "2023-11-16"
        }
      },
      {
        "cveId": "CVE-2023-4966",
        "firstExploited": "2023-11-01",
        "usage": "CitrixBleed session token theft used to hijack authenticated sessions and bypass MFA entirely.",
        "source": {
          "org": "CISA / FBI",
          "title": "Scattered Spider advisory (AA23-320A)",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a",
          "date": "2023-11-16"
        }
      }
    ],
    "relationships": [
      {
        "relatedActorId": "lockbit",
        "type": "operational-overlap",
        "confidence": "moderate",
        "note": "Both operate within the ransomware-as-a-service ecosystem; affiliates rotate between brands as law enforcement pressure lands."
      },
      {
        "relatedActorId": "cl0p",
        "type": "operational-overlap",
        "confidence": "low",
        "note": "Both financially motivated with data-theft extortion models; entirely different access tradecraft."
      }
    ],
    "reports": [
      {
        "org": "CISA / FBI",
        "title": "AA23-320A: Scattered Spider",
        "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a",
        "date": "2023-11-16"
      },
      {
        "org": "Microsoft Threat Intelligence",
        "title": "Octo Tempest crosses boundaries to facilitate extortion, encryption, and destruction",
        "url": "https://www.microsoft.com/en-us/security/blog/2023/10/25/octo-tempest-crosses-boundaries-to-facilitate-extortion-encryption-and-destruction/",
        "date": "2023-10-25"
      },
      {
        "org": "Unit 42",
        "title": "Muddled Libra's Evolution to the Cloud",
        "url": "https://unit42.paloaltonetworks.com/muddled-libra-evolution-to-cloud/",
        "date": "2024-06-12"
      },
      {
        "org": "Mandiant",
        "title": "UNC3944 Targets SaaS Applications",
        "url": "https://cloud.google.com/blog/topics/threat-intelligence/unc3944-targets-saas-applications",
        "date": "2024-09-19"
      }
    ],
    "campaigns": [
      {
        "id": "mgm-caesars",
        "actorId": "scattered-spider",
        "name": "MGM Resorts and Caesars Entertainment",
        "date": "2023-09-10",
        "significance": "landmark",
        "targetSectors": [
          "Retail & Hospitality",
          "Gaming"
        ],
        "targetCountries": [
          "United States"
        ],
        "cveIds": [],
        "summary": "Help-desk social engineering yielding privileged access to two major casino operators. MGM disclosed roughly $100 million in impact with hotel systems, slot machines, and digital room keys disabled for days; Caesars reportedly paid approximately $15 million. No exploit was involved — the access came from a phone call.",
        "sources": [
          {
            "org": "CISA / FBI",
            "title": "AA23-320A: Scattered Spider",
            "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a",
            "date": "2023-11-16"
          },
          {
            "org": "Microsoft Threat Intelligence",
            "title": "Octo Tempest crosses boundaries to facilitate extortion, encryption, and destruction",
            "url": "https://www.microsoft.com/en-us/security/blog/2023/10/25/octo-tempest-crosses-boundaries-to-facilitate-extortion-encryption-and-destruction/",
            "date": "2023-10-25"
          }
        ]
      }
    ],
    "flag": "🏴",
    "profile": "/apt/scattered-spider/"
  }
}