ATT&CKGroupsScattered Spider

Scattered Spider

G1015

Threat group.View on attack.mitre.org

About this group

Scattered Spider is a native English-speaking cybercriminal group active since at least 2022. The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors.
Scattered Spider relies heavily on social engineering, including impersonating IT and help-desk staff, to gain initial access, bypass multi-factor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain.
Scattered Spider had expanded into hybrid cloud and identity environments, using help-desk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365.

Techniques used64

Procedure examples64

TechniqueProcedure example
T1003.003
NTDS

Scattered Spider has extracted the `NTDS.dit` file by creating volume shadow copies of virtual domain controller disks.

T1006
Direct Volume Access

Scattered Spider has created volume shadow copies of virtual domain controller disks to extract the `NTDS.dit` file.

T1016
System Network Configuration Discovery

Scattered Spider has used network reconnaissance commands for discovery including `ping` and `nltest`.

T1018
Remote System Discovery

Scattered Spider can enumerate remote systems, such as VMware vCenter infrastructure.

T1021.001
Remote Desktop Protocol

Scattered Spider has used RDP to enable lateral movement.

T1021.004
SSH

Scattered Spider has used SSH to move laterally in victim environments and to access the vSphere vCenter Server GUI.

T1021.007
Cloud Services

Scattered Spider has also leveraged pre-existing AWS EC2 instances for lateral movement and data collection purposes.

T1041
Exfiltration Over C2 Channel

Scattered Spider has exfiltrated data from compromised VMware vCenter servers through an established C2 channel using the Teleport remote access tool.

T1059.001
PowerShell

Scattered Spider has used the PowerShell cmdlet Get-ADUser.

T1059.004
Unix Shell

Scattered Spider has used the command shell to upload and install the Teleport remote access tool to a compromised vCenter Server Appliance.

T1068
Exploitation for Privilege Escalation

Scattered Spider has deployed a malicious kernel driver through exploitation of CVE-2015-2291 in the Intel Ethernet diagnostics driver for Windows (iqvw64.sys).

T1069
Permission Groups Discovery

Scattered Spider has enumerated the vSphere Admins and ESX Admins groups in targeted environments.

T1069.002
Domain Groups

Scattered Spider has enumerated Active Directory security groups including through the use of ADExplorer, ADRecon.ps1, and Get-ADUser.

T1070.008
Clear Mailbox Data

Scattered Spider has manually deleted emails notifying users of suspicious account activity.

T1074
Data Staged

Scattered Spider stages data in a centralized database prior to exfiltration.

View all 64 procedure examples

Software9

Campaigns1

References6

  1. CISA Scattered Spider Advisory November 2023 Open source
    CISA. (2023, November 16). Cybersecurity Advisory: Scattered Spider (AA23-320A). Retrieved March 18, 2024.
  2. CrowdStrike Scattered Spider BYOVD January 2023 Open source
    CrowdStrike. (2023, January 10). SCATTERED SPIDER Exploits Windows Security Deficiencies with Bring-Your-Own-Vulnerable-Driver Tactic in Attempt to Bypass Endpoint Security. Retrieved July 5, 2023.
  3. CrowdStrike Scattered Spider Profile Open source
    CrowdStrike. (n.d.). Scattered Spider. Retrieved July 5, 2023.
  4. Crowdstrike TELCO BPO Campaign December 2022 Open source
    Parisi, T. (2022, December 2). Not a SIMulation: CrowdStrike Investigations Reveal Intrusion Campaign Targeting Telco and BPO Companies. Retrieved June 30, 2023.
  5. MSTIC Octo Tempest Operations October 2023 Open source
    Microsoft. (2023, October 25). Octo Tempest crosses boundaries to facilitate extortion, encryption, and destruction. Retrieved March 18, 2024.
  6. Mandiant UNC3944 May 2025 Open source
    Mandiant Incident Response. (2025, May 6). Defending Against UNC3944: Cybercrime Hardening Guidance from the Frontlines. Retrieved October 13, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.