Scattered Spider laying new eggs
ID: 6260e9ea-a685-5bb0-bdd5-247ceba025bd
STIX ID: report--6260e9ea-a685-5bb0-bdd5-247ceba025bd
Feed Name: Sekoia.io Blog
Date Published: 2024-02-22
Date Updated: 2026-04-29
Author: Pierre-Antoine D., Quentin Bourgue, Livia Tibirna and TDR (Threat Detection & Research)
Sekoia.io’s TDR analysis profiles the financially motivated Scattered Spider intrusion set (aka UNC3944/0ktapus/Octo Tempest) and documents its shift from social-engineering access brokerage to BlackCat ransomware affiliate activity; the report details extensive phone-based social engineering (phishing, smishing, SIM swapping, MFA bypass), recon/persistence techniques, exfiltration methods (Rclone, MEGAsync, transfer.sh, cloud storage), tooling/RMM usage, targeted sectors and high-profile victims, and provides IoCs (phishing domains and servers) and recommended monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
