G1015: Scattered Spider
Scattered Spider is a native English-speaking cybercriminal group active since at least 2022. CitationCrowdStrike Scattered Spider Profile CitationMSTIC Octo Tempest Operations October 2023 The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. CitationMSTIC Octo Tempest Operations October 2023 Scattered Spider relies heavily on social engineering, including impersonating IT and help-desk staff, to gain initial access, bypass multi-factor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. CitationCISA Scattered Spider Advisory November 2023 CitationCrowdStrike Scattered Spider BYOVD January 2023 CitationCrowdstrike TELCO BPO Campaign December 2022 Scattered Spider had expanded into hybrid cloud and identity environments, using help-desk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365. CitationMandiant UNC3944 May 2025
Security context for executives and security teams
Scattered Spider matters because MITRE describes a financially motivated group that turns people, identity workflows, and remote administration into paths into enterprise networks. The supplied ATT&CK description emphasizes help-desk and IT impersonation, MFA bypass, administrator access in Okta, AWS, and Office 365, EDR evasion, and ransomware use. For leaders, this is less a single malware problem than a test of identity governance, help-desk controls, cloud administration, SOC visibility, and incident response speed.
Executive priority
Prioritize this as an identity-led intrusion and resilience scenario. Executives should ask whether help-desk identity proofing, MFA reset/enrollment approvals, privileged access controls, cloud admin logging, and ransomware response plans would hold up under social engineering. Sectors named by MITRE include CRM providers, BPO, telecommunications, technology, gaming, hospitality, retail, MSP, manufacturing, and financial organizations, so third-party and service-provider exposure should also be reviewed where relevant.
Technical view
ATT&CK provides no official detection text for this group, so validation should be relationship-driven. The mapped behavior includes credential access against AD/NTDS, use of Mimikatz and LaZagne, remote access via RDP, SSH, cloud services, ConnectWise, ngrok, Tor, PowerShell and Unix shell execution, discovery of systems and permission groups, exfiltration over C2, mailbox-data clearing, exploitation for privilege escalation, and ransomware-related tooling such as BlackCat. SOC teams should test whether identity, endpoint, cloud, mail, network, and remote administration telemetry can be correlated around a suspicious help-desk/MFA event through privilege escalation, lateral movement, and exfiltration.
Likely telemetry
- Help-desk tickets, MFA reset/enrollment records, identity-proofing approvals, and administrative support workflow logs
- Identity provider authentication logs, MFA challenge outcomes, privileged role changes, and Okta-related administrator activity where applicable
- AWS and Office 365 audit logs, including cloud service logins, administrative actions, mailbox activity, and suspicious export/delete behavior
- Endpoint process, script, driver, and security-control tampering telemetry, especially PowerShell, Unix shell, credential dumping, and vulnerable-driver indicators
- Active Directory domain controller logs, NTDS access indicators, group membership discovery, and privileged account use
Detection direction
- Do not rely on malware signatures alone; validate detections that connect social engineering outcomes to identity changes, new sessions, privilege escalation, and remote access.
- Tune for high-risk help-desk events: MFA resets, device re-enrollment, password resets, account recovery, new admin assignments, and access from unusual networks or support contexts.
- Correlate cloud and on-premises identity activity because ATT&CK notes administrator access in Okta, AWS, and Office 365 and relationships include cloud-services lateral movement.
- Hunt for credential-access and AD targeting patterns, including Mimikatz/LaZagne use, NTDS access, domain group discovery, and unusual domain-controller interaction.
- Validate visibility for legitimate tools used in suspicious ways, including ConnectWise, ngrok, Tor, Rclone, RDP, and SSH; false positives will be common unless baselined by user, host, destination, and business purpose.
Mitigation priorities
- Strengthen help-desk and IT support identity-proofing before account recovery, MFA reset, device enrollment, or privileged access changes are approved.
- Reduce standing privilege across identity providers, cloud consoles, Office 365, AD, and remote administration tools; require strong approval and logging for administrative actions.
- Harden MFA processes against social engineering by controlling enrollment, reset, and recovery paths, not only user login prompts.
- Restrict and monitor remote administration, tunneling, and file synchronization tools; maintain an allowlist or documented business justification where feasible.
- Protect credential stores and domain controllers, limit access to NTDS-related artifacts, and monitor privileged group membership changes.
Additional notes and limits
This take is based on ATT&CK v19.1 object G1015 and its supplied relationships. The object names multiple aliases: Scattered Spider, Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944. Relationship context includes campaign C0027 targeting telecommunications and BPO companies in 2022 and a broad set of tools and techniques spanning identity, endpoint, cloud, remote access, discovery, credential access, exfiltration, and ransomware-related activity.
MITRE does not provide an official detection section or explicit platform list for the intrusion-set object itself. Platform and telemetry guidance here is inferred only from the supplied technique/software relationships and official description. Local control validation, sector exposure, and evidence of activity require environment-specific logs and incident data.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Scattered Spider
Scattered Spider is a native English-speaking cybercriminal group active since at least 2022. CitationCrowdStrike Scattered Spider Profile CitationMSTIC Octo Tempest Operations October 2023 The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. CitationMSTIC Octo Tempest Operations October 2023 Scattered Spider relies heavily on social engineering, including impersonating IT and help-desk staff, to gain initial access, bypass multi-factor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. CitationCISA Scattered Spider Advisory November 2023 CitationCrowdStrike Scattered Spider BYOVD January 2023 CitationCrowdstrike TELCO BPO Campaign December 2022 Scattered Spider had expanded into hybrid cloud and identity environments, using help-desk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365. CitationMandiant UNC3944 May 2025
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
