LiveActive security incident?Get immediate response
MITRE ATT&CK® Campaign

C0027: C0027

C0027 was a financially-motivated campaign linked to Scattered Spider that targeted telecommunications and business process outsourcing (BPO) companies from at least June through December of 2022. During C0027 Scattered Spider used various forms of social engineering, performed SIM swapping, and attempted to leverage access from victim environments to mobile carrier networks.CitationCrowdstrike TELCO BPO Campaign December 2022

EnterpriseC0027CampaignObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

C0027 matters because it combines financially motivated targeting of telecommunications and BPO environments with social engineering, SIM swapping, cloud/account abuse, and attempts to use victim access toward mobile carrier networks. For leaders, the key lesson is that identity operations, help desk processes, cloud administration, and remote access controls can become business-critical attack surfaces—not just technical controls.

Executive priority

Prioritize this as an identity and operational resilience scenario, especially for organizations with telecom, BPO, outsourced support, CRM, or carrier-adjacent access. Executives should ask whether MFA enrollment, SIM-swap-related workflows, privileged cloud role changes, remote access, and third-party access paths produce auditable evidence fast enough for incident response and compliance review. Budget and control decisions should focus on reducing social-engineering success, limiting valid-account blast radius, and proving visibility across cloud, identity provider, Windows domain, remote service, and collaboration platforms.

Technical view

ATT&CK provides no campaign-level detection text or platforms for C0027, so defenders should scope validation from the listed relationships. The campaign is attributed to Scattered Spider and uses techniques spanning initial access, persistence, privilege escalation, credential access, discovery, lateral movement, collection, command and control, and defense impairment. SOC and IR teams should validate coverage for voice-based social engineering, cloud account use, MFA/device registration changes, cloud role and credential additions, external remote service logons, public-facing application exposure, DCSync-style domain replication abuse, WMI execution, cloud and email account enumeration, SharePoint/cloud storage access, remote desktop software, proxy/tunneling behavior, web service C2, ingress tool transfer, network service discovery, and cloud instance creation.

Likely telemetry

  • Identity provider sign-in logs, conditional access decisions, MFA events, and device registration records
  • Help desk, account recovery, SIM-swap, and privileged support workflow records where applicable
  • Cloud audit logs for role assignment, credential/key addition, service principal/application changes, cloud account and group enumeration, and instance creation
  • VPN, Citrix, remote access gateway, and other external remote service authentication logs
  • Windows domain controller security logs and directory replication activity relevant to DCSync detection

Detection direction

  • Because official detection guidance is not provided, start with control-evidence validation: confirm the organization can reconstruct identity changes, remote access, cloud admin actions, and privileged directory activity across the full incident timeline.
  • Correlate suspicious valid-account activity with new MFA/device registration, added cloud credentials, added cloud roles, unusual cloud group/account enumeration, and access to collaboration or cloud storage repositories.
  • Tune detections for DCSync and Impacket-like activity around domain controllers, while accounting for legitimate backup, identity synchronization, and administrative replication activity.
  • Monitor WMI execution, remote desktop software, ingress tool transfer, and network service discovery together rather than as isolated events; each may be legitimate alone but material in sequence after unusual identity activity.
  • Review remote service access for impossible travel, new devices, atypical source networks, abnormal session duration, and access by accounts tied to support or administrative functions.

Mitigation priorities

  • Harden identity verification and help desk/account recovery workflows, especially MFA reset, device enrollment, privileged support, and SIM-swap-related processes where relevant.
  • Enforce least privilege for cloud and directory roles; regularly review who can add credentials, assign roles, register devices, or perform directory replication-sensitive actions.
  • Require strong MFA and monitor for new device registration or MFA factor changes; restrict self-service enrollment and recovery paths for privileged or high-risk users.
  • Reduce external remote service exposure through access policy, segmentation, strong authentication, logging, and regular review of inactive or overprivileged accounts.
  • Prioritize vulnerability management for Internet-facing applications and remote access services because T1190 and T1133 are in the campaign relationship set.
Additional notes and limits

This take is based on the official ATT&CK C0027 campaign description, the cited CrowdStrike reference entry, and ATT&CK relationships showing attribution to Scattered Spider and use of Impacket plus listed techniques. The strongest defensive interpretation is identity-centric: the supplied relationships emphasize valid cloud accounts, cloud role/credential changes, device registration, remote services, discovery, collection from cloud/SaaS repositories, and Windows domain credential-access behavior.

ATT&CK does not provide official detection text, campaign-level platforms, or campaign-level tactics for C0027 in the supplied fields. The telemetry and control guidance are therefore derived from the official relationships and must be validated against the local environment, actual cloud/SaaS stack, telecom/BPO exposure, logging retention, and support-process design. This summary does not assert current activity, customer exposure, or guaranteed detection coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

C0027

C0027 was a financially-motivated campaign linked to Scattered Spider that targeted telecommunications and business process outsourcing (BPO) companies from at least June through December of 2022. During C0027 Scattered Spider used various forms of social engineering, performed SIM swapping, and attempted to leverage access from victim environments to mobile carrier networks.CitationCrowdstrike TELCO BPO Campaign December 2022

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
243ae979ca72d3f9...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.