Scattered Spider
G10156 reportsAnalyst assessment — key judgments
- Signature techniques: T1556.006 (Multi-Factor Authentication), T1589.001 (Credentials), T1053.005 (Scheduled Task).
- Primary targeting: US, CN, GB.
- Activity declining: 0 report(s) in last 30d vs 2 prior (-100%).
- Hunt coverage 78% of 9 observed techniques (2 gap(s)).
- Assessment confidence: medium (61).
Activity & trend
Movement — last 30 days
Vulnerabilities in this actor's reporting · 1
- CVE-2026-22769KEV1 rpt
Overview
Scattered Spider is a native English-speaking cybercriminal group active since at least 2022. (Citation: CrowdStrike Scattered Spider Profile) (Citation: MSTIC Octo Tempest Operations October 2023) The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. (Citation: MSTIC Octo Tempest Operations October 2023) Scattered Spider relies heavily on social engineering, including impersonating IT and help-desk staff, to gain initial access, bypass multi-factor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. (Citation: CISA Scattered Spider Advisory November 2023) (Citation: CrowdStrike Scattered Spider BYOVD January 2023) (Citation: Crowdstrike TELCO BPO Campaign December 2022) Scattered Spider had expanded into hybrid cloud and identity environments, using help-desk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365. (Citation: Mandiant UNC3944 May 2025)
ATT&CK technique matrix
- T1556.006 · Multi-Factor Authenticationconf 652
- T1589.001 · Credentialsconf 652
- T1053.005 · Scheduled Taskconf 601
- T1590.005 · IP Addressesconf 601
- T1588.006 · Vulnerabilitiesconf 601
- T1552.003 · Shell Historyconf 601
- T1559 · Inter-Process Communicationconf 601
- T1078.003 · Local Accountsconf 601
- T1589.002 · Email Addressesconf 601
Threat catalogue · engineering roadmap
Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.
Infrastructure
Relationships
Activity
| Title | Source | Severity | Collected |
|---|