Scattered Spider

APT / StateG1015
Techniques (MITRE ATT&CK)64
SourceMITRE ATT&CK
0
Also known as:Roasted 0ktapusOcto TempestStorm-0875UNC3944

Vexday analysis

Scattered Spider (também identificado como Roasted 0ktapus, Octo Tempest, Storm-0875 e UNC3944) é um grupo criminoso de língua inglesa ativo desde pelo menos 2022, catalogado pelo MITRE ATT&CK sob o identificador G1015 com 64 técnicas documentadas. Inicialmente concentrado em provedores de CRM, empresas de terceirização de processos de negócio (BPO) e companhias de telecomunicações e tecnologia, o grupo expandiu suas operações em 2023 para os setores de jogos, hotelaria, varejo, provedores de serviços gerenciados (MSP), manufatura e serviços financeiros. Suas operações dependem fortemente de engenharia social, incluindo a personificação de equipes de TI e suporte técnico, para obter acesso inicial, contornar autenticação multifator (MFA) e comprometer redes corporativas. Ao grupo são atribuídas duas CVEs conhecidas.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity68
Impact: High
T1059.001T1098T1068T1003.003T1074T1041EXECExecutionPowerShellPERSPersistenceAccountManipulationPRIVPrivilege escalationExploitation forPrivilege Escalat…CREDCredential accessNTDSCOLLCollectionData StagedEXFILExfiltrationExfiltration OverC2 ChannelIMPACTImpactData Encrypted forImpact

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Techniques (MITRE ATT&CK) 64

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Exploited vulnerabilities 2

CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.

Known infrastructure 3

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

sha1_hashc5ec7e2ad924e832e49fbac9d0c82719b570e080MimiKatzthreatfox
md5_hash77c96f339974b65ae435313a8fcc3b35MimiKatzthreatfox
sha256_hash889cc3e793cb39889c7acc8e73a84973e9a08fcd69451f7b546509c74ffdda90MimiKatzthreatfox

Scattered Spider uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →