Threat actor
Scattered Spider
Also known as UNC3944Source [1], Scatter SwineSource [1], OktapusSource [1], Octo TempestSource [1], Storm-0875Source [1], Muddled LibraSource [1]
A joint FBI and CISA advisory describes Scattered Spider as a cybercriminal group that targets large companies and their contracted IT help desks.Source [1]
What authorities and investigators report
- Citing public reporting, the advisory says Scattered Spider actors posed as company IT or help-desk staff in phone calls or SMS messages to obtain credentials from employees.Source [1]
- Citing public reporting, the July 2025 update says the actors posed as employees to convince IT or help-desk staff to reset the employee's password and transfer the employee's MFA to a device they control.Source [1]
- Citing public reporting, the advisory says the actors sent repeated MFA notification prompts until employees accepted, and convinced mobile carriers to transfer a targeted user's phone number to a SIM card in their possession.Source [1]
- It says the actors have bought employee or contractor credentials on illicit marketplaces, and have compromised third-party services with access to several potential target organizations' networks.Source [1]
- It says that after convincing help-desk personnel to reset passwords or transfer MFA tokens, the actors performed account takeovers against users in SSO environments.Source [1]
- Per trusted third parties cited in the July 2025 update, the actors typically steal data for extortion and have used several ransomware variants, most recently DragonForce.Source [1]
Techniques
Attack vectors
Sources
- Scattered Spider (AA23-320A) — CISA, 2025-07-29
Last reviewed Oct 2, 2026