APT English-Speaking Cybercriminal Collective Active since 2022

Scattered Spider

Social engineering specialists. SIM swapping, helpdesk social engineering, Okta/Azure AD targeting.

Scroll

Scattered Spider is an English-speaking cybercriminal collective composed primarily of young adults and teenagers. The group specializes in social engineering — particularly helpdesk impersonation, SIM swapping, and MFA fatigue attacks — to compromise identity providers like Okta and Azure AD. They formed a formal alliance with ALPHV/BlackCat ransomware in 2023.

AttributeDetail
NamesScattered Spider / UNC3944 / Octo Tempest
AttributionEnglish-Speaking Cybercriminal Collective
Active Since2022
Primary FocusSocial engineering specialists. SIM swapping, helpdesk social engineering, Okta/Azure AD targeting.

Overview

Scattered Spider is an English-speaking cybercriminal collective composed primarily of young adults and teenagers. The group specializes in social engineering — particularly helpdesk impersonation, SIM swapping, and MFA fatigue attacks — to compromise identity providers like Okta and Azure AD. They formed a formal alliance with ALPHV/BlackCat ransomware in 2023.

Attribution

Scattered Spider / UNC3944 / Octo Tempest is attributed to English-Speaking Cybercriminal Collective, active since at least 2022. Social engineering specialists. SIM swapping, helpdesk social engineering, Okta/Azure AD targeting.

Notable Campaigns

MITRE ATT&CK Mapping

Technique IDTechniqueConfidence
T1566PhishingHigh
T1078Valid AccountsHigh
T1199Trusted RelationshipHigh
T1486Data Encrypted for ImpactHigh
T1621Multi-Factor Authentication Request GenerationHigh
T1656ImpersonationHigh

Detection & Defense

Recommended Defenses

Monitor for the TTPs listed above using your SIEM and EDR platforms. Prioritize patching of internet-facing applications and enforce MFA on all remote access. Mjolnir Security provides continuous threat hunting and monitoring for Scattered Spider activity patterns.

Mjolnir Security — Threat Intelligence & Response

Mjolnir Security provides 24/7 threat monitoring, incident response, and threat intelligence services. Contact us for threat hunting specifically targeting Scattered Spider TTPs in your environment.

Threat Hunting Incident Response Threat Intelligence SOC-as-a-Service

mjolnirsecurity.com — 24/7 Incident Response Hotline: +1 833 403 5875