Reconnaissance
1 technique
Assembles a convincing employee identity from LinkedIn, prior breach corpora and public org charts — job title, manager's name, office, start date. Enough to survive the questions a help desk actually asks.
Native English-speaking teenagers who talk their way past help desks. No exploits, no zero-days — just a convincing phone call.
Scattered Spider inverted the assumptions most enterprise security programmes are built on.
The group is composed largely of young, native English-speaking members based in the U.S. and U.K., loosely organised through the online community researchers call "the Com." That demographic detail is operationally decisive: the single most effective control against social engineering has historically been that the caller sounds foreign, reads from a script, and misuses idiom. Scattered Spider callers sound like colleagues, because they are culturally native to the organisations they target.
The core technique is a phone call to the IT help desk. The caller impersonates an employee — armed with real details harvested from LinkedIn and prior breaches — and asks for an MFA reset or a new device enrolment. Help desks exist to unblock people, are measured on resolution time, and are staffed by people whose job is to be helpful. The group has repeatedly obtained privileged access this way without a single exploit.
Where phone calls fail, it uses MFA fatigue (repeated push notifications until the target approves one), SIM swapping to intercept SMS codes, and adversary-in-the-middle phishing kits.
Its September 2023 attacks on MGM Resorts and Caesars Entertainment brought the model to public attention: MGM disclosed roughly $100 million in impact, with hotel systems, slot machines, and digital keys disabled for days; Caesars reportedly paid a ransom of about $15 million. The group has since worked with successive ransomware-as-a-service brands — ALPHV/BlackCat, then RansomHub, then DragonForce — and expanded into insurance, retail, and aviation.
Several members have been arrested and charged in the U.S. and U.K. Activity attributed to the broader community has continued regardless — the structure is a loose social network, not an organisation with a leadership to decapitate.
Down to the named unit where public evidence supports it.
A financially motivated criminal group with no state sponsorship. Multiple members have been arrested and charged: the U.S. Department of Justice charged five individuals in November 2024 over a phishing campaign against employees at companies nationwide, and further arrests have been made in the U.K. Members are largely young, native English speakers organised through online communities rather than a formal hierarchy, which has allowed attributed activity to continue after arrests.
Attributing sources
10 designators across 10 organisations.
1 designator is marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.
Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.
Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.
Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.
APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.
Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.
Constellation denotes attributed origin or motive, adopted in 2023 to replace ad-hoc naming.
Colour prefix encodes attributed origin (RedXxxx = China, BlueXxxx = Russia). TAG-## ('Threat Activity Group') is a provisional designator for clusters pending attribution.
Names activity clusters descriptively rather than by a fixed nation-state taxonomy, and generally adopts the prevailing community name for established state actors. Coverage skews toward commodity and eCrime threats seen in managed-detection telemetry.
'Earth <name>' for many state-nexus groups; older clusters retain descriptive names such as Pawn Storm.
U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.
Target sectors
Target geography
Custom tooling is a strong clustering signal; shared and commodity tooling is not.
Shared, commodity & living-off-the-land
The primary access vector — phone calls to IT support requesting MFA resets, made credible by native-speaker fluency and harvested personal detail.
Repeated authentication push notifications until the target approves one out of confusion or exhaustion.
Carrier social engineering to port a target's number and intercept SMS-based authentication codes.
Real-time credential proxies capturing session tokens to bypass MFA.
AnyDesk, TeamViewer, Splashtop, and ScreenConnect installed for persistent access — signed, allowed, and unremarkable.
Successive ransomware-as-a-service brands used as the monetisation layer; the group supplies access and negotiation, not encryption.
Voice and SMS phishing impersonating IT support, directing targets to credential harvesting pages.
Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.
| CVE | Product | Usage by Scattered Spider | ||
|---|---|---|---|---|
| CVE-2024-1709KEVransomware | 10.0 | ConnectWise ScreenConnectConnectWise | 1 Feb 2024 | ConnectWise ScreenConnect authentication bypass exploited for access to managed environments.SRCCISA / FBI ↗ |
| CVE-2023-4966KEVransomware | 9.4 | Citrix NetScalerCitrix | 1 Nov 2023 | CitrixBleed session token theft used to hijack authenticated sessions and bypass MFA entirely.SRCCISA / FBI ↗ |
| CVE-2015-2291 | — | — | 1 May 2023 | A vulnerable signed Intel Ethernet diagnostics driver loaded to terminate EDR processes from kernel space — bring-your-own-vulnerable-driver in place of exploit development.SRCCrowdStrike ↗ |
Actors sharing exploited CVEs
How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.
1 technique
Assembles a convincing employee identity from LinkedIn, prior breach corpora and public org charts — job title, manager's name, office, start date. Enough to survive the questions a help desk actually asks.
1 technique
A phone call. A native English speaker who sounds like a colleague asks IT support to reset MFA or enrol a new device. The help desk exists to unblock people, is measured on resolution time, and is staffed by people whose job is to be helpful — so it helps.
1 technique
Enrols an attacker-controlled device for MFA and installs commercial remote-management software — AnyDesk, TeamViewer, ScreenConnect. All signed, all reputable, all things a real IT department deploys.
1 technique
Impersonation in both directions: the employee to IT, and IT to the employee. Where tooling is needed, a vulnerable signed driver terminates the endpoint agent from kernel space.
3 techniques
Where the call fails, push bombing until an exhausted target approves, a SIM swap to intercept the SMS code, or an adversary-in-the-middle proxy that captures the session cookie and makes MFA irrelevant.
1 technique
Goes to the SaaS and code repositories directly, because that is where the data now lives — the endpoint was only ever the route to the identity.
1 technique·derived
Legitimate commercial RMM tools installed as durable access.
1 technique·derived
Exfiltration to Cloud Storage.
2 techniques
Locks out administrators, disables recovery paths, then hands off to whichever ransomware-as-a-service brand it is affiliated with that quarter. MGM disclosed roughly $100 million; Caesars reportedly paid about $15 million.
Scroll horizontally · characteristic chain across documented operations, not a single incident
Grouped in kill-chain order.
The group's signature — direct phone calls to help desks and employees
Enrolling attacker-controlled devices for MFA
Impersonating employees to IT support, and IT support to employees
Legitimate commercial RMM tools installed as durable access
Ransomware supplied by affiliated RaaS operations
Locking out administrators and disabling recovery paths during an intrusion
Help-desk social engineering yielding privileged access to two major casino operators. MGM disclosed roughly $100 million in impact with hotel systems, slot machines, and digital room keys disabled for days; Caesars reportedly paid approximately $15 million. No exploit was involved — the access came from a phone call.
Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.
Both operate within the ransomware-as-a-service ecosystem; affiliates rotate between brands as law enforcement pressure lands.
Both financially motivated with data-theft extortion models; entirely different access tradecraft.
Curated links to the reports that established what is known about this group.