Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G1015
MITRE ATT&CK Group

Scattered Spider (G1015)

Roasted 0ktapusOcto TempestStorm-0875UNC3944
ShareXLinkedInRedditHN

[Scattered Spider](https://attack.mitre.org/groups/G1015) is a native English-speaking cybercriminal group active since at least 2022. (Citation: CrowdStrike Scattered Spider Profile) (Citation: MSTIC Octo Tempest Operations October 2023) The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. (Citation: MSTIC Octo Tempest Operations October 2023) [Scattered Spider](https://attack.mitre.org/groups/G1015) relies heavily on social engineering, including impersonating IT and help-desk staff, to gain initial access, bypass multi-factor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. (Citation: CISA Scattered Spider Advisory November 2023) (Citation: CrowdStrike Scattered Spider BYOVD January 2023) (Citation: Crowdstrike TELCO BPO Campaign December 2022) [Scattered Spider](https://attack.mitre.org/groups/G1015) had expanded into hybrid cloud and identity environments, using help-desk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365. (Citation: Mandiant UNC3944 May 2025)

▪Techniques used (66)

T1598Phishing for InformationT1685Disable or Modify ToolsT1553.002Code SigningT1556.009Conditional Access PoliciesT1580Cloud Infrastructure DiscoveryT1105Ingress Tool TransferT1114.003Email Forwarding RuleT1598.003Spearphishing LinkT1078Valid AccountsT1003.003NTDST1041Exfiltration Over C2 ChannelT1087.002Domain AccountT1484.002Trust ModificationT1087Account DiscoveryT1564.008Email Hiding RulesT1585.001Social Media AccountsT1539Steal Web Session CookieT1588.002ToolT1552.004Private KeysT1589Gather Victim Identity InformationT1538Cloud Service DashboardT1486Data Encrypted for ImpactT1059.004Unix ShellT1133External Remote ServicesT1021.004SSHT1204User ExecutionT1556.006Multi-Factor AuthenticationT1684.001ImpersonationT1583.001DomainsT1016System Network Configuration DiscoveryT1083File and Directory DiscoveryT1543.002Systemd ServiceT1219.002Remote Desktop SoftwareT1657Financial TheftT1213.003Code RepositoriesT1098.003Additional Cloud RolesT1069Permission Groups DiscoveryT1621Multi-Factor Authentication Request GenerationT1082System Information DiscoveryT1021.001Remote Desktop ProtocolT1098Account ManipulationT1213.005Messaging ApplicationsT1068Exploitation for Privilege EscalationT1090ProxyT1530Data from Cloud StorageT1217Browser Information DiscoveryT1006Direct Volume AccessT1136Create AccountT1490Inhibit System RecoveryT1018Remote System DiscoveryT1069.002Domain GroupsT1059.001PowerShellT1555.005Password ManagersT1567.002Exfiltration to Cloud StorageT1598.004Spearphishing VoiceT1074Data StagedT1078.004Cloud AccountsT1070.008Clear Mailbox DataT1021.007Cloud ServicesT1572Protocol TunnelingT1578.002Create Cloud InstanceT1552.001Credentials In FilesT1114Email CollectionT1588.001MalwareT1451SIM Card SwapT1660Phishing

▪Software used (9)

S0670WarzoneRATmalwareS1040RclonetoolS0349LaZagnetoolS0183TortoolS0002MimikatztoolS1148Raccoon StealermalwareS0508ngroktoolS1068BlackCatmalwareS0591ConnectWisetool
G1015on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.