Scattered Spider, also tracked here as GOLD HARVEST, is a loosely organized English-speaking cybercriminal collective associated with the broader "The Com" ecosystem. The group is financially motivated and is known for social-engineering-led intrusions that frequently begin with impersonation of IT or help-desk personnel. Its operations commonly involve abuse of remote monitoring and management tools, multi-factor authentication bypass, and theft of credentials and session material through commodity infostealers such as Vidar and Raccoon. The actor is known to target help desks as an initial access vector, steal bulk data, and in some cases deploy ransomware. Scattered Spider has operated as a ransomware affiliate rather than solely as a standalone ransomware developer. It has been linked to use of ALPHV in the 2023 MGM Resorts intrusion, use of RansomHub in attacks during 2024, and reported deployment of DragonForce ransomware in attacks against UK retailers in 2025, including the widely reported Marks and Spencer incident. Reported tradecraft includes credential theft, session hijacking through theft of browser-saved cookies and session tokens, social engineering for initial access, and post-compromise data exfiltration. The group overlaps with other English-speaking cybercriminal actors tied to underground forums and encrypted chat channels, and has been associated with opportunistic, high-impact intrusions against enterprise environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
English-speaking cybercriminal group noted only as having significant overlaps with GOLD CRYSTAL and affiliation to 'The Com' ecosystem.
Loosely organized cybercriminal collective associated with The Com that conducts intrusions using social engineering, credential theft, RMM abuse, and MFA bypass. It reportedly deployed DragonForce in attacks on UK retailers and previously acted as an affiliate for ALPHV and RansomHub.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.