DEFCON 3 · ELEVATED OBSERVATORY STATUS
04:24:00 UTC
EXPLORE DIRECTORY
LAST SYNCHRONIZED: 2026-08-30
groupactive

Scattered Spider (UNC3944 / Octo Tempest / Starfraud)

KNOWN ALIASES: UNC3944 · Octo Tempest · 0ktapus · Scatter Swine · Muddled Libra
EXECUTIVE INTELLIGENCE SUMMARY

Hyper-aggressive, English-speaking cybercrime syndicate mastering identity provider compromise, SIM swapping, helpdesk social engineering, and cloud infrastructure ransom.

Renowned for sophisticated voice phishing (vishing) targeting IT service desks to reset MFA tokens and bypass Okta/Entra ID authenticators. Once inside, they weaponize BlackCat/ALPHV ransomware and exfiltrate proprietary source code and customer databases.

MAJOR ATTRIBUTED OPERATIONS
2023 · Las Vegas Casino & Resort Conglomerate ExtortionTARGET: MGM Resorts & Caesars Entertainment

10-minute LinkedIn-based helpdesk call resulting in full Okta tenant admin access and total ESXi virtualization cluster lockup.

SOURCE CITATIONS & ATTESTATIONS (1)
Mandiant Special Report: Why UNC3944 is the Most Aggressive Identity ThreatGoogle Cloud Mandiant

UNC3944: The Rise of Advanced Cloud Social Engineering

TELEMETRY CARDID: group-scattered-spider
ENTITY TYPE
group
STATE JURISDICTION / ORIGIN
United States / United Kingdom / Canada (The Com Ecosystem)
INDEXED TAGS
#cybercrime#vishing#helpdesk_social_engineering#sim_swapping#okta_bypass#cloud_ransom