Scattered Spider (UNC3944 / Octo Tempest) adversary-emulation playbook — help-desk vishing → MFA takeover → cloud/SaaS/identity privilege expansion → RMM persistence → data-theft extortion. Use when emulating identity-first social-engineering eCrime against a help-desk/IdP estate. Triggers on: 'emulate Scattered Spider', 'UNC3944', 'Octo Tempest', '0ktapus', 'help desk social engineering', 'MFA fatigue', 'SIM swap', 'identity attack'.
72
89%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Critical
Do not install without reviewing
Tier-2 native-English-speaking eCrime collective. Their edge is social engineering: impersonating employees to the IT help desk to drive password resets and MFA transfers, then pivoting fast through the identity provider (Okta / Entra ID) into cloud and SaaS, deploying legitimate RMM for persistence, and finishing with data-theft extortion / ransomware. Authorized red-team emulation only — every action runs under the engagement RoE.
plan/threat-profile.json){
"engagement_name": "<fill>",
"actor_name": "Scattered Spider-like (UNC3944 / Octo Tempest)",
"actor_aliases": ["UNC3944", "Octo Tempest", "Muddled Libra", "Roasted 0ktapus", "Scatter Swine"],
"group_id": "G1015",
"tier": "tier-2",
"sophistication": "high",
"motivation": "financial",
"initial_access": ["T1656", "T1598", "T1566.004", "T1078.004"],
"key_ttps": ["T1621", "T1556.006", "T1098.005", "T1078.004", "T1219", "T1213", "T1486", "T1657"],
"tools": ["Authorized test persona (vishing)", "AnyDesk / ConnectWise (engagement-owned)", "Sliver", "NetExec", "Impacket"],
"infrastructure": ["Spoofed/marked caller-ID test line", "Look-alike SSO phishing page", "Attacker-registered MFA device (engagement-controlled)", "Rogue VM in victim vSphere/Azure"],
"recent_cti_delta": "2023-2025: help-desk impersonation + MFA fatigue + SIM swap; registers its own MFA, creates rogue VMs in vSphere/Azure; pivoted to impersonating employees against third-party IT; ransomware affiliate ALPHV -> RansomHub -> DragonForce.",
"confidence": "probable"
}| # | Phase | MITRE | Emulated action | Executing agent → skill |
|---|---|---|---|---|
| 1 | Recon (PII) | T1589 | Harvest employee names, roles, phone numbers, help-desk reset process | recon → /skills/standard/recon/osint/SKILL.md, /skills/standard/osint/SKILL.md |
| 2 | Initial Access | T1656 / T1598 / T1566.004 | Vish the help desk as a target employee → password reset + MFA transfer | phisher → /skills/standard/phisher/SKILL.md |
| 3 | MFA bypass | T1621 / T1556.006 | MFA-fatigue push OR register attacker-controlled MFA device | phisher/exploit → /skills/standard/phisher/SKILL.md, /skills/standard/exploit/web/oauth/SKILL.md |
| 4 | Cloud foothold | T1078.004 | Sign in to Okta/Entra/AWS as the reset account | cloud → /skills/standard/cloud/aws-iam-enum/SKILL.md, /skills/standard/cloud/azure-managed-identity/SKILL.md |
| 5 | Scope expansion | T1098.003 / T1098.005 | Self-assign apps in Okta; add roles/credentials; passrole chains | cloud → /skills/standard/cloud/aws-iam-passrole-chain/SKILL.md |
| 6 | Persistence | T1219 | Deploy engagement-owned RMM (AnyDesk/ConnectWise); create rogue VM | post-exploit → /skills/standard/post-exploit/lateral-movement/SKILL.md, /skills/standard/post-exploit/c2-sliver/SKILL.md |
| 7 | On-prem pivot (hybrid) | T1558.003 / T1003 | BloodHound the AD; Kerberoast; dump creds | ad → /skills/standard/ad/bloodhound-query/SKILL.md, /skills/standard/ad/kerberoasting/SKILL.md |
| 8 | Collection | T1213 | Mine SharePoint/Confluence/Slack for secrets + PII (canary) | post-exploit → /skills/standard/post-exploit/credential-access/SKILL.md |
| 9 | Exfiltration | T1567.002 | Stage + exfil the scoped/canary data set | post-exploit → /skills/standard/post-exploit/reporting/SKILL.md |
| 10 | Impact (CANARY) | T1486 / T1657 | Demonstrate ransomware/financial-theft capability on canary only | post-exploit → /skills/standard/post-exploit/reporting/SKILL.md |
conops.json)recon — OSINT/PII + help-desk reset-process recon (1).initial-access — vishing → password reset + MFA takeover → cloud login (2-4).post-exploit — Okta/IAM scope expansion, RMM persistence, optional on-prem AD pivot, SaaS collection (5-8).c2 — Sliver / RMM session (within row 6).exfiltration — data theft → extortion demonstration on canary (9-10)./skills/standard/phisher/lure-deconfliction/SKILL.md). Name exactly which staff/roles are
in scope.EMERGENCY abort trigger:
"real customer data exfiltrated, real funds moved, or production system encrypted."deconfliction.json + cleanup.json.0cf691e
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.