Full Report
This blog covers Group-IB’s overview of Scattered Spider, backed by Group-IB’s proprietary intelligence, providing additional information to what has already been reported publicly, with added clarification on 0ktapus and how it is related to Scattered Spider.
Analysis Summary
Based on the Group-IB intelligence report provided, here is the structured summary regarding the threat actor known as Scattered Spider.
# Threat Actor: Scattered Spider
## Attribution & Identity
* **Identification:** A sophisticated threat actor group characterized by their mastery of social engineering and identity-based attacks.
* **Known Aliases:** UNC3944, Roasted 0ktapus, Starfraud.
* **Associated Groups:** The actor is closely linked to—and sometimes synonymous with—the **0ktapus** campaign/group. While 0ktapus originally referred to a specific campaign targeting Okta credentials, the name now describes the broader cluster of activity attributed to Scattered Spider.
* **Composition:** Primarily composed of young, native English-speaking individuals, often associated with the "Com" or "Luke" community.
## Activity Summary
Scattered Spider is known for high-profile breaches involving large-scale social engineering. Their recent campaigns involve bypassing Multi-Factor Authentication (MFA) to gain initial access to corporate environments. They transitioned from simple credential harvesting to complex data exfiltration and, more recently, ransomware deployment (specifically as an affiliate for ALPHV/BlackCat). Their activity is defined by persistent lateral movement within cloud environments (SaaS, IaaS) after the initial compromise.
## Tactics, Techniques & Procedures
Scattered Spider is notable for "Identity-centric" attacks rather than traditional malware-heavy approaches.
* **Vishing (Voice Phishing):** Calling corporate help desks, impersonating employees to reset passwords or MFA devices.
* **Smishing (SMS Phishing):** Sending text messages with links to fraudulent login pages (0ktapus-style) to harvest credentials and MFA codes.
* **MFA Fatigue/Push Bombing:** Bombarding victims with MFA push notifications until they approve the request (T1621).
* **SIM Swapping:** Moving a victim's phone number to an actor-controlled SIM to intercept SMS-based MFA.
* **Port-out Fraud:** Utilizing port-out PINs to transfer mobile numbers between carriers.
* **Cloud Persistence:** Creating new federated identity providers or adding unauthorized devices to Okta/Azure AD (T1098).
* **EDR Evasion:** Utilizing Bring Your Own Vulnerable Driver (BYOVD) techniques to disable security software.
**MITRE ATT&CK IDs Mentioned/Associated:**
* **T1566.002:** Phishing: Spearphishing Link
* **T1456:** Multi-Factor Authentication Evasion
* **T1078:** Valid Accounts
* **T1098:** Account Manipulation
* **T1539:** Steal Web Session Cookie
## Targeting
* **Sectors:** Technology, Business Process Outsourcing (BPO), Telecommunications, Hospitality, Retail, and Financial Services.
* **Geography:** Predominantly United States, Canada, and Western Europe.
* **Victims:** Large enterprises with complex identity infrastructures (e.g., MGM Resorts, Caesars Entertainment, and various tech companies using Okta).
## Tools & Infrastructure
* **Malware Families:**
* **Lugh:** A specialized tool for interaction with internal systems.
* **Stolen Credentials:** The primary "tool" used for access.
* **Ransomware:** ALPHV/BlackCat.
* **Remote Access Tools:** AnyDesk, TeamViewer, and Fleetdeck.io for persistence.
* **Infrastructure:**
* **C2/Phishing Domains:** Often mimic legitimate SSO portals (e.g., `[company]-okta[.]com`, `sso-[company][.]com`).
* **Telegram:** Used for command and control and data exfiltration notifications.
* **Defanged Examples:** `okta-helpdesk[.]com`, `mfa-auth[.]net`.
## Implications
Scattered Spider represents a shift in the threat landscape where human-centric vulnerabilities (social engineering) are prioritized over technical exploits. Their ability to navigate internal corporate documentation to learn how to escalate privileges makes them highly dangerous. Their affiliation with ransomware groups suggests a shift toward purely financial extortion, leveraging the high-pressure environment of data leaks.
## Mitigations
* **Phishing-Resistant MFA:** Implement FIDO2-compliant hardware keys (e.g., YubiKeys) to replace SMS and push-based MFA.
* **Help Desk Verification:** Establish strict out-of-band verification processes for password resets (e.g., manager approval or video verification).
* **Monitor Identity Logs:** Audit Okta and Azure AD logs for the addition of new MFA devices, new administrative accounts, or logins from unknown VPNs/IPs.
* **Carrier Locks:** Encourage employees in sensitive roles to set up "Port-out PINs" and "Sim-Lock" features with their mobile service providers to prevent SIM swapping.