logo

Scattered Spider, The Group That Blends Digital Attacks With Real-World Violence

ID: 5d14370d-3b0d-56bc-947d-493984d3be1a

STIX ID: report--5d14370d-3b0d-56bc-947d-493984d3be1a

Feed Name: iVerify Blog

Threat Score
78/100

Date Published: 2026-03-03

Date Updated: 2026-04-28

...
...

This report profiles Scattered Spider (aka UNC3944 / Roasted 0ktapus), a decentralized cybercrime group active since mid-2022 that specializes in social engineering (including MFA bombing and smishing), BYOVD bypasses, and use of legitimate remote-access and tunneling tools to compromise high-profile corporate targets (MGM, Caesars, Twilio, DoorDash, MailChimp, Riot Games). It describes their tactics for lateral movement and cloud/SaaS data exfiltration, notes recent arrests of alleged members, maps techniques to MITRE ATT&CK, and recommends mobile-focused defensive measures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.