Skip to content
Multiple / Non-stateCriminalActiveMITRE G1015

Scattered Spider

Native English-speaking teenagers who talk their way past help desks. No exploits, no zero-days — just a convincing phone call.

Open MITRE Navigator layer ↗Download profile JSON
Active
2022–present
Motivation
Financial Gain
Aliases
10
Exploited CVEs
3
ATT&CK techniques
12
Cited sources
9

Overview

Scattered Spider inverted the assumptions most enterprise security programmes are built on.

The group is composed largely of young, native English-speaking members based in the U.S. and U.K., loosely organised through the online community researchers call "the Com." That demographic detail is operationally decisive: the single most effective control against social engineering has historically been that the caller sounds foreign, reads from a script, and misuses idiom. Scattered Spider callers sound like colleagues, because they are culturally native to the organisations they target.

The core technique is a phone call to the IT help desk. The caller impersonates an employee — armed with real details harvested from LinkedIn and prior breaches — and asks for an MFA reset or a new device enrolment. Help desks exist to unblock people, are measured on resolution time, and are staffed by people whose job is to be helpful. The group has repeatedly obtained privileged access this way without a single exploit.

Where phone calls fail, it uses MFA fatigue (repeated push notifications until the target approves one), SIM swapping to intercept SMS codes, and adversary-in-the-middle phishing kits.

Its September 2023 attacks on MGM Resorts and Caesars Entertainment brought the model to public attention: MGM disclosed roughly $100 million in impact, with hotel systems, slot machines, and digital keys disabled for days; Caesars reportedly paid a ransom of about $15 million. The group has since worked with successive ransomware-as-a-service brands — ALPHV/BlackCat, then RansomHub, then DragonForce — and expanded into insurance, retail, and aviation.

Several members have been arrested and charged in the U.S. and U.K. Activity attributed to the broader community has continued regardless — the structure is a loose social network, not an organisation with a leadership to decapitate.

Attribution

Down to the named unit where public evidence supports it.

None — financially motivated criminal groupLoosely organised, primarily U.S. and U.K. based membersConfirmed

A financially motivated criminal group with no state sponsorship. Multiple members have been arrested and charged: the U.S. Department of Justice charged five individuals in November 2024 over a phishing campaign against employees at companies nationwide, and further arrests have been made in the U.K. Members are largely young, native English speakers organised through online communities rather than a formal hierarchy, which has allowed attributed activity to continue after arrests.

Attributing sources

Cross-vendor naming crosswalk

10 designators across 10 organisations.

1 designator is marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.

MITRE ATT&CK

index ↗
  • Scattered Spider

Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.

Microsoft Threat Intelligence

index ↗
  • Octo Tempest

Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.

CrowdStrike

index ↗
  • Scattered Spider

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Mandiant / Google Threat Intelligence

index ↗
  • UNC3944

APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.

Secureworks CTU

index ↗
  • GOLD HARVESTER

Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.

Palo Alto Networks Unit 42

index ↗
  • Muddled Libra

Constellation denotes attributed origin or motive, adopted in 2023 to replace ad-hoc naming.

Recorded Future Insikt Group

index ↗
  • Scattered Spider

Colour prefix encodes attributed origin (RedXxxx = China, BlueXxxx = Russia). TAG-## ('Threat Activity Group') is a provisional designator for clusters pending attribution.

Red Canary

index ↗
  • Scattered SpiderExtensively covered in Red Canary detection research

Names activity clusters descriptively rather than by a fixed nation-state taxonomy, and generally adopts the prevailing community name for established state actors. Coverage skews toward commodity and eCrime threats seen in managed-detection telemetry.

Trend Micro

index ↗
  • Water CurupirapartialPartial overlap with tracked activity

'Earth <name>' for many state-nexus groups; older clusters retain descriptive names such as Pawn Storm.

CISA / NSA / FBI

index ↗
  • Scattered Spider

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Shared, commodity & living-off-the-land

Help desk social engineeringlotl

The primary access vector — phone calls to IT support requesting MFA resets, made credible by native-speaker fluency and harvested personal detail.

MFA fatiguelotl

Repeated authentication push notifications until the target approves one out of confusion or exhaustion.

SIM swappinglotl

Carrier social engineering to port a target's number and intercept SMS-based authentication codes.

Evilginx / AiTM kitsframework

Real-time credential proxies capturing session tokens to bypass MFA.

Legitimate RMM toolsutility

AnyDesk, TeamViewer, Splashtop, and ScreenConnect installed for persistent access — signed, allowed, and unremarkable.

ALPHV / RansomHub / DragonForceransomware

Successive ransomware-as-a-service brands used as the monetisation layer; the group supplies access and negotiation, not encryption.

Vishing and smishinglotl

Voice and SMS phishing impersonating IT support, directing targets to credential harvesting pages.

Exploited vulnerabilities

Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.

CVEUsage by Scattered Spider
CVE-2024-1709KEVransomware10.01 Feb 2024ConnectWise ScreenConnect authentication bypass exploited for access to managed environments.SRCCISA / FBI
CVE-2023-4966KEVransomware9.41 Nov 2023CitrixBleed session token theft used to hijack authenticated sessions and bypass MFA entirely.SRCCISA / FBI
CVE-2015-22911 May 2023A vulnerable signed Intel Ethernet diagnostics driver loaded to terminate EDR processes from kernel space — bring-your-own-vulnerable-driver in place of exploit development.SRCCrowdStrike

Actors sharing exploited CVEs

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

9 stages · 12 techniques
  1. 01

    Reconnaissance

    1 technique

    Assembles a convincing employee identity from LinkedIn, prior breach corpora and public org charts — job title, manager's name, office, start date. Enough to survive the questions a help desk actually asks.

  2. 02

    Initial Access

    1 technique

    A phone call. A native English speaker who sounds like a colleague asks IT support to reset MFA or enrol a new device. The help desk exists to unblock people, is measured on resolution time, and is staffed by people whose job is to be helpful — so it helps.

  3. 03

    Persistence

    1 technique

    Enrols an attacker-controlled device for MFA and installs commercial remote-management software — AnyDesk, TeamViewer, ScreenConnect. All signed, all reputable, all things a real IT department deploys.

  4. 04

    Defense Evasion

    1 technique

    Impersonation in both directions: the employee to IT, and IT to the employee. Where tooling is needed, a vulnerable signed driver terminates the endpoint agent from kernel space.

  5. 09

    Impact

    2 techniques

    Locks out administrators, disables recovery paths, then hands off to whichever ransomware-as-a-service brand it is affiliated with that quarter. MGM disclosed roughly $100 million; Caesars reportedly paid about $15 million.

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

Open in Navigator ↗
12 techniques across 9 tactics · 7 with actor-specific notes

Reconnaissance

1

Persistence

1

Defense Evasion

1

Command and Control

1

Impact

2

Campaign timeline

  1. landmark

    MGM Resorts and Caesars Entertainment

    Help-desk social engineering yielding privileged access to two major casino operators. MGM disclosed roughly $100 million in impact with hotel systems, slot machines, and digital room keys disabled for days; Caesars reportedly paid approximately $15 million. No exploit was involved — the access came from a phone call.

    Retail & HospitalityGaming

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.