logo

Scattered Spider laying new eggs

ID: 6260e9ea-a685-5bb0-bdd5-247ceba025bd

STIX ID: report--6260e9ea-a685-5bb0-bdd5-247ceba025bd

Feed Name: Sekoia.io Blog

Threat Score
85/100

Date Published: 2024-02-22

Date Updated: 2026-04-29

Author: Pierre-Antoine D., Quentin Bourgue, Livia Tibirna and TDR (Threat Detection & Research)

...
...

Sekoia.io’s TDR analysis profiles the financially motivated Scattered Spider intrusion set (aka UNC3944/0ktapus/Octo Tempest) and documents its shift from social-engineering access brokerage to BlackCat ransomware affiliate activity; the report details extensive phone-based social engineering (phishing, smishing, SIM swapping, MFA bypass), recon/persistence techniques, exfiltration methods (Rclone, MEGAsync, transfer.sh, cloud storage), tooling/RMM usage, targeted sectors and high-profile victims, and provides IoCs (phishing domains and servers) and recommended monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.