They didn’t use a zero-day. They didn’t breach a firewall. They made a phone call. One call to an IT help desk, and Scattered Spider pulled off a £300 million attack on Marks and Spencer.
If you work in security and haven’t fully unpacked this threat actor yet, this is the profile you need.
This article covers who Scattered Spider is, how they evolved, their key Tactics, Techniques, and Procedures (TTPs), the malware in their arsenal, and what your team should be doing right now to defend against them. Let’s get into it.
Background
Scattered Spider isn’t a threat group in the traditional sense, and that’s what makes them so dangerous.
Most of us learned threat actors with a clean mental model. On one side, you have nation-state Advanced Persistent Threats (APTs) like Cozy Bear and APT41, running long-term espionage campaigns backed by state actors. On the other hand, you have your Eastern European ransomware crews, organized hierarchically, running like businesses. Two distinct worlds.
Then Scattered Spider blew that model up.
They are a loose, decentralized collective of what can only be described as digital natives. Most members are between 16 and 25 years old. They are native English speakers, predominantly from the UK, US, and Canada, and they are deeply familiar with Western corporate culture. That last part? That is their weapon.
They came up through something called the COM, short for “the community.” An informal ecosystem of cybercriminals who operate through Telegram and Discord, where reputation is everything and status is earned by the scale of your hacks. A lot of these actors started out doing SIM swapping (hijacking phone numbers to steal cryptocurrency) or building cheats for Minecraft and Roblox.
Not exactly the profile you’d imagine for someone who could bring down an FTSE 100 company.

But those early activities built exactly the right skill set.
- Social engineering.
- Understanding platform mechanics.
- Knowing how to manipulate people under pressure.
Then they scaled it up massively.
The COM is not a single organization. It is a fluid, reputation-based ecosystem where criminal skills are traded and developed. This decentralized structure makes it incredibly difficult for law enforcement to disrupt, because there is no single chain of command to sever. When one node is taken down, others simply step up.
The group is also tracked under several alternative designations. If you see references to UNC3944, Octo Tempest, Scatter Swine, Muddled Libra, or Star Fraud in vendor reporting, these all refer to overlapping activity attributed to the same collective.
As of early 2026, they have evolved further, merging with LAPSUS$ and ShinyHunters to form the Scattered LAPSES Hunters (SLH) alliance. Think of it as a criminal supergroup: a federated brand of extortionists with centralized infrastructure for ransomware deployment, data leak sites, and target reconnaissance.
We’ll get into what that means for you shortly. But first, let’s look at how this group got here.
Timeline
Understanding how Scattered Spider evolved tells you a lot about where they are heading next.
2022: The Oktapus Campaign

This is where many defenders first noticed Scattered Spider. They launched a massive SMS phishing campaign targeting over 130 organizations, including Twilio, Cloudflare, and DoorDash. They built convincing fake Okta login pages and used them to harvest credentials and session tokens at scale.
Its simplicity should have been the alarm bell. No sophisticated malware. No complex exploit chain. Just a convincing phishing site and the patience to use stolen sessions before they expired.
2023: The MGM and Caesars Attacks

This is the campaign that put them on the map for the wider industry. The MGM Resorts breach in September 2023 was attributed to Scattered Spider. Slot machines went dark across Las Vegas. Hotel key cards stopped working. A massive operational disruption, all because someone called the MGM IT help desk and convinced them to reset credentials for a privileged account.
What made it worse? Caesars Entertainment reportedly paid approximately $15 million in ransom to avoid the same fate, half of the attackers’ original $30 million demand. That story only emerged later when a disgruntled affiliate leaked it.
Two of the world’s biggest casino operators: one refused to pay and suffered weeks of disruption; the other paid tens of millions to keep it quiet. That is the business model. That is the leverage this group goes after.
2024: Law Enforcement Responds
By 2024, the group’s high-profile attacks had attracted serious law enforcement attention on both sides of the Atlantic.
In January 2024, Noah Michael Urban (“Sosa”, “King Bob”), 20, was arrested in Florida. In June 2024, Tyler Robert Buchanan (“tylerb”), 22, and believed to be the group’s alleged leader, was arrested in Spain while attempting to board a flight to Italy. Spanish police reported he was carrying Bitcoin worth approximately $27 million at the time of arrest.
In July 2024, a 17-year-old from Walsall, UK, was arrested in connection with the MGM attacks. By November 2024, the US Department of Justice unsealed charges against five individuals, including Ahmed Elbadawy, Evans Osiebo, Joel Evans, Urban, and Buchanan, for conspiracy to commit wire fraud and aggravated identity theft.
These were real outcomes. Seven arrests in a single year. But the group preserved.
2025: The Scattered LAPSUS$ Hunters Era

Instead of fragmenting, Scattered Spider adapted. Senior members were being sentenced, but simultaneously, Scattered Spider, LAPSUS$, and ShinyHunters formalized an alliance. They pivoted from pure data extortion into full ransomware operations, and the targeting became more aggressive than ever.
In this era, the group:
- Ran AI-powered vishing campaigns against Salesforce customers
- Hit Qantas Airlines, exposing data on approximately six million passengers
- Launched their own bespoke ransomware platform: Shiny Spider
- Deployed DragonForce ransomware against Marks and Spencer, Co-op, and Harrods
- Targeted JLR, Visa, PNC Financial Services, and multiple US and UK retailers
The pattern here is worth noting in your threat models. The arrests didn’t deter them. They adapted, rebranded, and came back with a more industrialized capability.
The M&S Deep Dive

The M&S breach timeline tells you everything you need to know about how this group operates in practice. It began when an attacker contacted a help desk agent at Tata Consultancy Services (TCS), one of M&S’s third-party IT vendors. Classic Scattered Spider playbook: they’d already done the LinkedIn reconnaissance, had the employee details in hand, and talked the agent into resetting credentials for a privileged account.
For the next two months, they were quietly inside the TCS environment. Patient. Methodical. Moving laterally and mapping M&S’s infrastructure through that vendor connection. They identified VMware vCenter as the high-value target.
Then, on Easter weekend (maximum disruption, minimal staff), DragonForce ransomware was deployed across M&S’s virtualized infrastructure.
Contactless payments went down. Online ordering died. Staff were writing inventory on paper with a pen. M&S publicly confirmed the attack had wiped an estimated £300 million from operating profit, with market capitalization dropping by over £700 million in the aftermath.
M&S’s own perimeter security was probably fine. The attackers never needed to touch it. They went through the vendor. That is the playbook. Your security perimeter is only as strong as the weakest link in your supply chain.
Tactics, Techniques, and Procedures (TTPs)
This is where it gets really interesting for us as security analysts. Let me walk through how this group operates at every stage of the attack chain.
Initial Access
Scattered Spider uses three primary initial access techniques.

The first is vishing, or voice phishing. They conduct reconnaissance on LinkedIn to build convincing employee personas, and then they call your IT help desk. By the time they make the call, they already know the employee’s ID number, their manager’s name, and sometimes even their home address, all of which have been gathered through Open Source Intelligence (OSINT). They ask for a password reset or a new Multi-Factor Authentication (MFA) device enrolment.
Most help desks are incentivized on call handling time and user satisfaction. Security is often an afterthought in that workflow. Scattered Spider exploits that gap ruthlessly. The TCS agent who reset credentials in the M&S breach was just doing their job. They were trying to be helpful. And that is the problem.
The second technique is MFA fatigue, sometimes called push bombing. If they’ve already obtained your credentials (bought off a stealer log or compromised through phishing), they’ll trigger repeated MFA push notifications on your phone, over and over again, at two in the morning, until you just hit approve to make it stop. It’s not sophisticated. But it works because it exploits human psychology, not software vulnerabilities.
The third technique is Adversary-in-the-Middle (AiTM) phishing, using toolkits like Evilginx. They set up a convincing fake Single Sign-On (SSO) portal (Okta, Microsoft Entra ID, whatever your target organization uses).
When the victim logs in, the proxy captures not just the credentials, but the authenticated session token in real time. MFA is irrelevant at that point. They’ve got a valid session. That 2022 Oktapus campaign that hit 130 organizations? That is exactly what they did at scale.
Post-Compromise
Once they’re in, Scattered Spider is exceptional at staying quiet.

They rely heavily on legitimate tools already on your network, such as AnyDesk, TeamViewer, and ScreenConnect. These remote monitoring and management (RMM) tools are allow-listed by your Endpoint Detection and Response (EDR), so no alerts fire when they’re used.
For cloud environments, they’ll use AWS Systems Manager for host enumeration, exfiltrate data to Mega.nz, and target VMware vCenter to escalate privileges across your virtualized environment. They will also abuse OAuth app registrations in Okta, Azure AD, and Salesforce to maintain persistent API-level access long after the initial compromise.
Even if you reset the compromised user’s password and re-enroll their MFA, the threat actor still has a foothold if they have registered a malicious OAuth application.
MITRE ATT&CK Mapping
The CISA advisory on Scattered Spider, updated as recently as July 2025, provides the authoritative government-level TTP mapping for this group. For those building detections, here’s how their core techniques map to the MITRE ATT&CK framework:
| TTP | MITRE ID | Description |
|---|---|---|
| Vishing / LinkedIn Recon | T1598 | Phishing for Information |
| MFA Push Bombing | T1621 | MFA Request Generation |
| Session Token Theft | T1539 | Steal Web Session Cookie |
| RMM Tool Abuse | T1219 | Remote Access Software |
| Data Exfiltration to Cloud | T1537 | Transfer Data to Cloud Account |
If you want to build a detection engineering strategy around these TTPs, the MITRE ATT&CK Navigator is a great tool for visualizing coverage gaps in your defenses. You can also use the Diamond Model of Intrusion Analysis to structure your understanding of Scattered Spider across the adversary, infrastructure, capability, and victim dimensions, which is useful if you’re building a formal threat actor profile for your organization.
Malware
Spectre RAT
Silent Push’s threat research, published in April 2025, confirmed that Scattered Spider has been deploying an updated version of Spectre RAT throughout their 2025 campaigns. It is a C++ based Remote Access Trojan (RAT) that is modular, capable of process enumeration, software discovery, and pulling additional payloads from a Command and Control (C2) server.
Per Silent Push’s analysis, it uses XOR encoding and Base64 for communication, employs mutex logic to prevent multiple instances from running simultaneously, and abuses code signing certificates to blend in with legitimate software.

What makes it particularly noteworthy is its use of the legitimate Sysinternals tool PSinfo.exe for software discovery. This is a Living Off the Land Binary (LOLBin) that specifically targets your security tools, so the group knows what they are up against before they move further. If you see PSinfo.exe executing in unusual contexts, treat that as a high-fidelity signal of a potential Scattered Spider intrusion.
Silent Push has also published a Spectre RAT string decoder and C2 emulator to help defenders analyze the malware in their own environments.
ShinyHunters and the Shiny Spider RaaS Platform
A note on terminology here, because it matters. ShinyHunters is the threat actor group that merged with Scattered Spider and LAPSUS$ to form the SLH alliance. Shiny Spider is a custom Ransomware-as-a-Service (RaaS) platform, written in Go and launched in late 2025, believed to have been developed as part of that alliance’s capability build-out.

Shiny Spider hooks Event Tracing for Windows (ETW) to stop encryption activity from being logged to the Windows Event Viewer. If you are relying on Windows event logs alone to detect ransomware activity, you will be blind to it. It also deletes shadow volume copies and fills free space with random data to prevent forensic recovery. That is not just encryption; that is the deliberate destruction of your ability to recover.
DragonForce Ransomware
DragonForce was the weapon deployed against M&S and, per the updated CISA advisory, is the ransomware variant most recently associated with high-profile Scattered Spider operations.
It is particularly devastating when deployed against VMware vCenter, allowing attackers to encrypt an entire virtualized environment in a single operation, bypassing traditional endpoint controls entirely. Your EDR on the guest VMs is ineffective when the attack occurs at the hypervisor level.
Defense Recommendations
Let me tie each of these recommendations directly back to the techniques we just covered.
1. Lock Down Your Help Desk
Every major Scattered Spider intrusion, from M&S to MGM to Qantas, started with a help desk agent doing what they were trained to do: being helpful. The fix isn’t a new tool. It’s a process change.
- Implement a verified callback protocol. Before any privileged action is performed (password reset, MFA device enrolment, account unlock), the agent must call back the pre-registered number already on file, not the number the caller provides.
- Mandate video verification for high-risk requests. Where possible, require a live video call for any privileged account action. AI voice cloning can defeat audio-only verification; video raises the bar significantly.
- Define your high-risk actions list. Not every help desk call is equal. Credential resets and MFA re-enrolments for privileged accounts should require step-up verification that lower-risk calls do not.
- Run quarterly vishing simulations. Use actual voice call scripts that mirror the pretexts Scattered Spider deploys: the locked-out executive, the remote employee who can’t access their phone, the contractor from a named third-party vendor. Your people need to have heard these scripts before the real one comes in.
A single control (verified callbacks) would have disrupted the majority of Scattered Spider’s documented intrusions.
2. Upgrade to Phishing-Resistant MFA
Your current MFA solution is probably fishable. Let’s upgrade it.
- Deploy FIDO2-compliant authentication for privileged accounts first. Hardware security keys like YubiKeys, or device-bound passkeys, are cryptographically tied to the physical device and the specific domain. An EvilEngineX proxy cannot intercept them because the key will not authenticate against a spoofed domain.
- Eliminate push-based MFA for any account with administrative access. Push bombing works because push-based MFA lets users approve without context. Remove that option entirely for your highest-risk accounts.
- Deploy risk-based authentication. If someone is logging in from a new country at 3 am on an unrecognized device, your Identity Access Management (IAM) platform should automatically raise friction, not wave them through just because they tapped a notification.
- Expand phishing-resistant MFA over time. Start with help desk operators, IT administrators, and anyone with identity management permissions. Build a roadmap to broader coverage.
3. Audit Your OAuth Applications
Regularly audit connected applications in your SSO environment. If an account that was recently reset has approved an unfamiliar app, that is a red flag. Scattered Spider abuses OAuth registrations to maintain persistent API-level access long after you think you’ve evicted them.
Even resetting a password and re-enrolling in MFA are not enough if a malicious OAuth app is still in your environment with active API permissions.
4. Treat Your Supply Chain as Part of Your Perimeter
Annual vendor security questionnaires are not going to cut it against this group. You need to extend your security requirements contractually into your supply chain. That means:
- Continuous monitoring of your critical vendors’ security posture
- Contractual breach notification timelines
- Data minimization by default (if your customer support vendor doesn’t need passport numbers, they shouldn’t be storing them)
- Explicit MFA and verification requirements for any vendor help desk that has access to your environment
For more on building a structured approach to this, see our guide to data collection methods for CTI and our intelligence collection plan framework.
5. Isolate Your Virtualization Layer
If Scattered Spider reaches VMware vCenter, it is game over for your entire infrastructure. You must isolate your VMware ESXi management interfaces from your corporate network. This is not a nice-to-have. It is the single architectural control that could have limited the blast radius of the M&S attack to a recoverable level.
6. Tune Your Detections
Maintain a definitive allow-list of approved RMM tools and enforce it through your EDR. If AnyDesk or TeamViewer runs on a host where it shouldn’t be present, it should trigger an alert immediately. Also, tune your detections to catch:
ntdsutil.exerunning outside of scheduled maintenance windowsPSinfo.exeexecuting in unusual contexts (this is how Spectre RAT performs software discovery, per Silent Push’s analysis)- Unusual OAuth application registrations following recent credential resets
- Data egress to mega[.]nz (and other file-sharing platforms)
Defense Recommendations Summary
- Verified Callback Protocol
This single process change would have disrupted the majority of Scattered Spider’s documented intrusions. It is low-cost and high-impact. - Phishing-Resistant MFA
FIDO2 hardware keys neutralize both push bombing and AiTM attacks simultaneously, removing two of the group’s three primary initial access techniques in one move. - Supply Chain Security
Extending security requirements contractually into your vendor ecosystem closes the vector that enabled both the M&S and Qantas breaches. - VMware Isolation
Isolating your hypervisor management plane limits the blast radius of any ransomware deployment to a recoverable scope, rather than catastrophic. - Detection Tuning
Alerting on LOLBin abuse and RMM anomalies gives you high-fidelity signals of post-compromise activity before ransomware is ever deployed.
Future Predictions
Let’s talk about where this group is heading in 2026 and beyond.
Extortion as a Service: The Most Significant Structural Development
SLH alliance is moving toward a fully industrialized extortion-as-a-service model. Small affiliate crews operating under the SLH brand, with centralized back-end infrastructure for ransomware deployment, negotiation, data leak sites, and target reconnaissance.
More campaigns are running simultaneously, with less-sophisticated actors behind each one, plugging into the SLH ecosystem for the capabilities they couldn’t build on their own.
This mirrors the evolution of Ransomware-as-a-Service (RaaS) we saw with groups like REvil and Conti, but with a social-engineering specialization layered on top that is uniquely dangerous given the rise of AI voice tools. The retail wave of 2025 (M&S, Co-op, Harrods) is the proof-of-concept run for this model at scale.
AI-Enhanced Social Engineering
AI voice cloning is now an active, deployed capability, not a theoretical future threat. The 2025 Salesforce campaign used automated AI voice agents to scale vishing operations. With as little as 30 seconds of audio, they can generate a synthetic voice convincing enough to fool a help desk agent under time pressure. Campaigns that previously required a skilled social engineer per call can now run automatically across thousands of targets.
Critical Infrastructure Is Now in Scope
The JLR incident in late 2025 demonstrated an important point. These actors don’t need industrial control system-specific exploits to cause industrial impact. If they can get into your Enterprise Resource Planning (ERP) system or your VMware environment, the operational technology downstream grinds to a halt. That is the vector for critical infrastructure impact, and it is already happening.
Law Enforcement Is Making Progress, But It Is Not a Deterrent
Between 2024 and 2025, seven Scattered Spider members were arrested, including Tyler Buchanan, who was extradited from Spain to the US in April 2025, and two UK teenagers, Thalha Jubair and Owen Flowers, who were charged by the NCA in September 2025 in connection with the Transport for London hack.
These are real outcomes, and the individuals involved face serious consequences. Noah Urban, who pleaded guilty in early 2025, faces a potential five decades in prison and has agreed to pay $13 million in restitution.
But the group’s decentralized structure makes it resilient to decapitation. When a senior member is arrested, someone else in the COM steps up, often using the arrested member’s exploits to build their own reputation. The SLH alliance, announced while sentencing was being handed down, tells you everything you need to know about deterrence. Or rather, the lack of it.
Conclusion
Scattered Spider represents a genuine shift in how cybercriminals operate. They don’t operate from a state-sponsored bunker. They are young, English-speaking, and culturally fluent in the environments they are targeting. And they have figured out that your identity infrastructure and your human processes are softer targets than your perimeter firewalls.
The organizations that weather this threat the best are those that treat their help desks as security controls rather than operational overhead, those that have moved to phishing-resistant MFA, and those that have genuinely extended their security perimeter into their supply chains.
Build your threat profile around Scattered Spider. Map their TTPs to your environment using the MITRE ATT&CK. Find the gaps. And fix the human processes before the next phone call comes in. Good luck!
References:
- https://analyst1.com/threat-actors/scattered-spider/
- https://brandefense.io/blog/scattered-spider-apt-2025/
- https://www.levelblue.com/blogs/spiderlabs-blog/scattered-lapsuss-hunters-anatomy-of-a-federated-cybercriminal-brand
- https://www.silentpush.com/blog/scattered-spider-2025/
- https://reliaquest.com/blog/zendesk-scattered-lapsus-hunters-latest-target/
- https://www.picussecurity.com/resource/blog/tracking-scattered-spider-through-identity-attacks-and-token-theft
- https://www.zerofox.com/intelligence/flash-report-powerful-new-raas-from-scattered-lapsus-hunters/
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a
Frequently Asked Questions
What Is Scattered Spider?
Scattered Spider (also tracked as UNC3944, Octo Tempest, Scatter Swine, and Muddled Libra) is a loosely organized cybercriminal collective primarily composed of native English-speaking young adults from the UK, US, and Canada.
They are known for highly sophisticated social engineering attacks, including vishing, MFA fatigue, and AiTM phishing, targeting large enterprises across finance, hospitality, retail, and aviation. As of 2025, they have merged with LAPSUS$ and ShinyHunters to form the Scattered LAPSES Hunters (SLH) alliance.
How Does Scattered Spider Get Initial Access?
Scattered Spider primarily uses three initial access techniques: vishing (calling IT help desks while impersonating employees using OSINT-gathered details to request credential resets), MFA fatigue attacks (push bombing victims with repeated authentication requests until they approve), and Adversary-in-the-Middle phishing using toolkits like Evilginx to steal live session tokens and bypass MFA entirely.
What Malware Does Scattered Spider Use?
The group’s primary malware includes Spectre RAT (a C++ Remote Access Trojan documented by Silent Push that uses PSinfo.exe for security tool discovery, XOR+Base64 encoding for C2 communication, and code signing abuse to evade detection), the Shiny Spider RaaS platform (a custom Go-based ransomware that hooks ETW to evade Windows event log detection and deletes shadow copies), and DragonForce ransomware (deployed against VMware vCenter for mass infrastructure encryption, as confirmed in the M&S attack).
What Is the Best Defense Against Scattered Spider Attacks?
The five most impactful controls are: a verified callback protocol for all privileged help desk actions, FIDO2-compliant phishing-resistant MFA for privileged accounts, regular OAuth application audits, isolation of VMware ESXi management interfaces from the corporate network, and contractual extension of security requirements into your vendor supply chain.
Is Scattered Spider Still Active in 2026?
Yes. Despite seven arrests in 2024 and 2025, including the alleged leader, Tyler Buchanan, the group has demonstrated structural resilience due to its decentralized COM-based organization. Under the SLH alliance, the group is moving toward an industrialized extortion-as-a-service model, incorporating AI voice cloning into vishing operations and continuing to target major enterprises across retail, aviation, finance, and critical infrastructure.



