EXPLORE DIRECTORY
LAST SYNCHRONIZED: 2026-08-30TLP:CLEAR
groupactive
Scattered Spider (UNC3944 / Octo Tempest / Starfraud)
KNOWN ALIASES: UNC3944 · Octo Tempest · 0ktapus · Scatter Swine · Muddled Libra
EXECUTIVE INTELLIGENCE SUMMARY
Hyper-aggressive, English-speaking cybercrime syndicate mastering identity provider compromise, SIM swapping, helpdesk social engineering, and cloud infrastructure ransom.
Renowned for sophisticated voice phishing (vishing) targeting IT service desks to reset MFA tokens and bypass Okta/Entra ID authenticators. Once inside, they weaponize BlackCat/ALPHV ransomware and exfiltrate proprietary source code and customer databases.
MAJOR ATTRIBUTED OPERATIONS
2023 · Las Vegas Casino & Resort Conglomerate ExtortionTARGET: MGM Resorts & Caesars Entertainment
10-minute LinkedIn-based helpdesk call resulting in full Okta tenant admin access and total ESXi virtualization cluster lockup.
SOURCE CITATIONS & ATTESTATIONS (1)
Mandiant Special Report: Why UNC3944 is the Most Aggressive Identity ThreatGoogle Cloud Mandiant
UNC3944: The Rise of Advanced Cloud Social Engineering
TELEMETRY CARDID: group-scattered-spider
ENTITY TYPE
group
STATE JURISDICTION / ORIGIN
United States / United Kingdom / Canada (The Com Ecosystem)
INDEXED TAGS
#cybercrime#vishing#helpdesk_social_engineering#sim_swapping#okta_bypass#cloud_ransom
CONNECTED ENTITIES (2)VIEW IN GRAPH →