Avatier

Threat actor

Scattered Spider

Also known as UNC3944Source [1], Scatter SwineSource [1], OktapusSource [1], Octo TempestSource [1], Storm-0875Source [1], Muddled LibraSource [1]

A joint FBI and CISA advisory describes Scattered Spider as a cybercriminal group that targets large companies and their contracted IT help desks.Source [1]

What authorities and investigators report

  • Citing public reporting, the advisory says Scattered Spider actors posed as company IT or help-desk staff in phone calls or SMS messages to obtain credentials from employees.Source [1]
  • Citing public reporting, the July 2025 update says the actors posed as employees to convince IT or help-desk staff to reset the employee's password and transfer the employee's MFA to a device they control.Source [1]
  • Citing public reporting, the advisory says the actors sent repeated MFA notification prompts until employees accepted, and convinced mobile carriers to transfer a targeted user's phone number to a SIM card in their possession.Source [1]
  • It says the actors have bought employee or contractor credentials on illicit marketplaces, and have compromised third-party services with access to several potential target organizations' networks.Source [1]
  • It says that after convincing help-desk personnel to reset passwords or transfer MFA tokens, the actors performed account takeovers against users in SSO environments.Source [1]
  • Per trusted third parties cited in the July 2025 update, the actors typically steal data for extortion and have used several ransomware variants, most recently DragonForce.Source [1]

Techniques

Attack vectors

Sources

  1. Scattered Spider (AA23-320A) — CISA, 2025-07-29

Last reviewed Oct 2, 2026