Scattered Spider

☆ pin
MITRE G1015Also known as SCATTERED SPIDER, Muddled Libra, ScatteredSpider, Octo Tempest, UNC3944, 0ktapus, 0sect, Scattered Lapsus$ Hunters, Scatter Swine, Starfraud, The Com, Scattered Spider
Reports
31
First seen
Sep 14, 2023
Last seen
Aug 7, 2026
Motivation
Financial

Relationships

Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.

Targeting

Victim regions
×1
×7
United Kingdom×7
United States×6
Japan×1

Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.

Top ATT&CK techniques

T1486 Data Encrypted for Impact ×16T1566 Phishing ×15T1078 Valid Accounts ×12T1190 Exploit Public-Facing Application ×11T1041 Exfiltration Over C2 Channel ×10T1005 Data from Local System ×9T1566.002 Phishing: Spearphishing Link ×6T1219 Remote Access Software ×5T1598 Phishing for Information ×5T1555 Credentials from Password Stores ×5T1110 Brute Force ×5T1021 Remote Services ×4

Indicators

cve ×97filename ×18domain ×10registry_key ×3url ×1

Indicator values are available on Pro and via the API.

Associated CVEs

Recent reports

High

CrowdStrike Threat Hunts for Shell Command Obfuscation on VMware ESX

CrowdStrike Blog
High

Cyber Brief July 2026 – EU Threat Intelligence Summary

CERT-EU Threat Intel
High

Leading Scattered Spider members sentenced to 66 months for Transport for London cyberattack

CyberScoop
Critical

Scattered Spider Operatives Sentenced to 5.5 Years for £29M TfL Ransomware Attack

The Hacker News
Critical

Scattered Spider members sentenced to five years for Transport for London hack

Bleeping Computer
High

Scattered Spider members sentenced to 5.5 years for £29M Transport for London cyberattack

The Record (Recorded Future News)
High

ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories

The Hacker News
High

FBI Traces Scattered Spider Hacker Using Windows Device ID in Luxury Jewelry Retailer Breach

The Hacker News
High

Weekly Cybersecurity Recap: Proxy Botnets, Browser Ransomware, RATs, and Credential Stealers

The Hacker News
High

Scattered Spider member Peter Stokes extradited to US on cybercrime charges

CyberScoop
High

Scattered Spider member Peter Stokes extradited to US for ransomware and extortion charges

Bleeping Computer
High

Teen suspect in Scattered Spider hacks extradited to US

The Record (Recorded Future News)
High

19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges

The Hacker News
High

Insurance giant Aflac discloses data breach after subsidiary hack

Bleeping Computer
High

ThreatsDay Bulletin: Smart TV Proxyware, curl Vulnerabilities, API Platform Flaws, and Ransomware Trends

The Hacker News
High

Scattered Spider Members Plead Guilty in Transport for London Cyberattack

KrebsOnSecurity
High

Scattered Spider members plead guilty to hacking Transport for London

Bleeping Computer
High

Two Scattered Spider members plead guilty in Transport for London cyberattack

The Record (Recorded Future News)
Critical

DragonForce ransomware uses custom Backdoor.Turn malware to hide C2 traffic in Microsoft Teams relays

Bleeping Computer
High

Threats to the 2026 FIFA World Cup: Physical Security, Cyber, and Influence Operations Risk Assessment

Recorded Future Insikt
unrated

2026 World Cup: Cyber Attack Surface and Threat Assessment

Palo Alto Unit 42
Info

Inside the RaaS Ecosystem: Operators, Affiliates & Attack Tradecraft

Huntress Blog
High

CrowdStrike 2026 Financial Services Threat Landscape Report Overview

CrowdStrike Blog
High

'Scattered Spider' member pleads guilty to wire fraud and identity theft

KrebsOnSecurity
Medium

Why LinkedIn is a hunting ground for threat actors – and how to protect yourself

ESET WeLiveSecurity
High

Risky Business #810 — Data extortion attacks have a silver lining

Risky Business
High

Risky Business #799 — Multiple critical vulnerabilities and breaches across tech vendors

Risky Business
High

Infostealers Crash Course: A Tradecraft Tuesday Recap

Huntress Blog
unrated

Scattered Spider hijacking MX records; Lumma Stealer, Qakbot takedowns

Risky Business
Medium

Defender Exclusions: How Adversaries Abuse Microsoft Defender Settings

Huntress Blog

This page shows data on a 7-day delay. Free accounts get the full delayed feed; real-time reports, indicators, and the API start at $29/mo.