Scattered Spider is a financially motivated, predominantly native-English-speaking cybercriminal collective active since at least May 2022, with members primarily in the United Kingdom and United States. It emerged from the online criminal community known as the Com and operates as a dispersed network rather than a tightly centralized organization. It is also tracked as 0ktapus, UNC3944, Muddled Libra, Octo Tempest, Scatter Swine, Scattered Swine, DEV-0971, STORM-0875, and LUCR-3. Its targeting initially concentrated on telecommunications, technology companies, and business process outsourcing providers before expanding into casinos, hotels, healthcare, pharmaceuticals, financial services, retail, and professional services. Prominent victims include MGM Resorts and Clorox, with targeting concentrated on large US organizations and also extending to the United Kingdom. The collective specializes in identity-centric intrusions combining targeted phishing and social engineering with abuse of legitimate accounts. Operators impersonate employees, new hires, and IT support personnel to obtain credentials, induce password resets, enroll authentication devices, or persuade users to grant remote access. Techniques include SMS and voice phishing, impersonating domains, SIM swapping, and MFA-fatigue attacks. Its familiarity with English-speaking workplaces helps operators manipulate help desks and onboarding processes. Scattered Spider has targeted Okta customers for identity credentials and abused identity-provider permissions to access cloud and SaaS applications. Following initial access, operators conduct reconnaissance, escalate privileges, move laterally, and exfiltrate data. They maintain access through backdoors, legitimate remote-management tools such as ScreenConnect, TeamViewer, and FleetDeck, and ngrok tunnels. Defense evasion includes disabling security products, compromising security accounts, staging activity in attacker-created virtual machines, and exploiting vulnerable drivers, including the Intel Ethernet diagnostics driver affected by CVE-2015-2291, to disable EDR from kernel space. Scattered Spider has operated as an ALPHV/BlackCat ransomware affiliate and conducted double-extortion attacks involving data theft followed by encryption. It has also deployed DragonForce and RansomHub ransomware, including staging a RansomHub encryptor inside a compromised VMware ESXi environment.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
66 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
28 malware families attributed to this actor across reporting.
23 additional families tracked in Mallory.
20 CVEs this actor has used in observed campaigns. 20 of them exploited in the wild.
The PDB path iqvw64e.pdb is the symbol name for iqvw64e.sys, the Intel Ethernet diagnostics driver — the canonical Bring-Your-Own-Vulnerable-Driver target (CVE-2015-2291), abused by Scattered Spider, BlackByte, and Lazarus/AppleJeus to disable EDR from the kernel.
The CVE-2025-61882 campaign is particularly instructive. CrowdStrike assessed with moderate confidence that GRACEFUL SPIDER was involved in mass exploitation of that vulnerability... Exploitation had begun nearly two months earlier on August 9, 2025, well before Oracle's public disclosure.
Additionally, Scattered Spider has exploited CVE-2021-35464 which is a flaw in the ForgeRock AM server. ForgeRock AM server versions before 7.0 have a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages... remote code execution can be triggered by sending a single crafted /ccversion/* request to the server.
VMware ESXi hypervisors joined to an Active Directory domain consider any member of a domain group named “ESX Admins” to have full administrative access by default.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
15 more CVEs tied to this actor tracked in Mallory.
289 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as abusing a vulnerable Intel Ethernet diagnostics driver to disable endpoint detection and response (EDR). The content does not attribute the analyzed AI-analysis evasion malware to Scattered Spider.
Mentioned as background for abusing a vulnerable Intel Ethernet diagnostics driver to disable endpoint detection and response (EDR). The content does not attribute the analyzed AI-evasion malware to this group.
Referenced as a historical comparison for data-extortion threats against UK organizations, not as an attributed participant in the ASOS incident. The access techniques are discussed collectively rather than tied to a specific Scattered Spider operation.
Mentioned only as a constituent group of Scattered LAPSUS$ Hunters; no independent operations or techniques are described.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.