Adversary-emulation profile for Scattered Spider (UNC3944/Octo Tempest), a financially motivated social-engineering-led intrusion group, mapped to ATT&CK G1015 and Decepticon tooling.
49
53%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Critical
Do not install without reviewing
Fix and improve this skill with Tessl
tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/scattered-spider/SKILL.mdScattered Spider (MITRE ATT&CK G1015) is a financially motivated, predominantly native English-speaking cybercriminal collective active since at least 2022 and widely linked to the loosely affiliated "The Com" social network. The group is exceptional not for novel malware but for aggressive, high-tempo social engineering of human identity processes: it phones and SMS-phishes help desks and employees, impersonates IT staff, bypasses MFA (push bombing, SIM swapping, attacker-registered tokens), and rapidly pivots into cloud identity (Microsoft Entra ID, Okta, AWS, Azure) and virtualization (VMware ESXi/vCenter) before staging data theft and ransomware. It began with the 2022 "0ktapus" Okta-credential phishing wave, escalated to the high-profile 2023 MGM Resorts and Caesars Entertainment intrusions, and through 2024–2025 operated as an affiliate of multiple ransomware-as-a-service brands (BlackCat/ALPHV, RansomHub, Qilin, DragonForce), hitting retail, insurance, and aviation. This profile teaches Decepticon to emulate G1015's signature identity-centric TTPs inside an authorized engagement and helps the blue cell anticipate detection.
T1657 Financial Theft). There is no credible espionage, destructive-only, or influence mandate; destruction (encryption) is in service of extortion.T1583.001 Acquire Infrastructure: Domains — registers lookalike/SSO-spoofing domains (e.g. victim-helpdesk[.]com, victim-sso[.]com).T1585.001 Establish Accounts: Social Media — builds fake personas; uses LinkedIn for target profiling.T1588.001 / T1588.002 Obtain Capabilities (Malware/Tools) — acquires info-stealers, RATs, ransomware, and offensive tools (RustScan, LinPEAS, aws_consoler, rsocx, Level RMM).T1102 Web Service — stages/downloads tooling from file.io, GitHub, paste.ee.T1598.004 / T1566.004 Spearphishing Voice (vishing) — calls help desks/employees impersonating IT to trigger password and MFA resets; signature technique.T1660 / T1598.003 Phishing (mobile / spearphishing link) — SMS smishing to credential-harvesting portals mimicking SSO.T1598.001 Spearphishing Service — Telegram/Teams messages impersonating IT personnel.T1451 SIM-Card Swap — social-engineers carriers to port victim numbers and intercept SMS OTPs.T1190 Exploit Public-Facing Application — opportunistic (e.g., CVE-2021-35464 in ForgeRock OpenAM).T1133 External Remote Services — abuses VPNs, Citrix, and remote-access tooling for entry.T1078 / T1078.004 Valid Accounts (incl. Cloud) — logs in with socially-engineered credentials; compromised Entra ID/Azure accounts.T1199 Trusted Relationship — pivots through MSPs, BPOs, and third-party contact-center platforms.T1621 MFA Request Generation — push-bombing / MFA-fatigue until a victim approves.T1204 User Execution — directs impersonated victims to install RMM agents.T1219.002 Remote Desktop Software — deploys TeamViewer, AnyDesk, LogMeIn, ConnectWise, ngrok-based access.T1059.001 PowerShell — e.g., Get-ADUser and recon scripting.T1059.004 Unix Shell — installs Teleport and tooling on Linux/ESXi.T1047 Windows Management Instrumentation — via Impacket for remote execution/lateral movement.T1098.005 Device Registration — registers attacker MFA devices/endpoints for durable access through VPN.T1136 Create Account — creates new identities in the victim tenant/domain.T1098 / T1098.001 / T1098.003 Account Manipulation — adds accounts to privileged groups (e.g., ESX Admins), adds cloud credentials, assigns admin roles.T1556.006 Modify Authentication Process: MFA — registers own MFA tokens post-compromise.T1484.002 Domain Trust Modification — adds a rogue federated IdP to the SSO tenant for backdoor authentication.T1543.002 / T1547.005 Systemd Service / SSP — Teleport persistence on Linux; Mimikatz SSP.T1556.009 Conditional Access Policies — adds trusted locations / weakens CA to bypass MFA for controlled accounts.T1068 Exploitation for Privilege Escalation — has deployed a malicious kernel driver (BYOVD via CVE-2015-2291).T1548.002 Bypass UAC — via tooling (BlackCat, WarzoneRAT).T1685 Disable or Modify Tools / T1562 Impair Defenses — uninstalls/disables EDR and security agents.T1564.008 Email Hiding Rules / T1070.008 Clear Mailbox Data — auto-deletes vendor security alert emails; deletes traces of its own account activity.T1553.002 Code Signing — abuses self-signed and stolen certificates (e.g., NVIDIA, Global Software LLC).T1027 Obfuscated Files / T1134 Access Token Manipulation — malware-delivered obfuscation and token abuse.T1003 / T1003.003 / T1003.006 OS Credential Dumping (Mimikatz, LaZagne), NTDS extraction via shadow copies, and DCSync.T1555.005 Password Managers — hunts HashiCorp Vault and PAM solutions.T1539 Steal Web Session Cookie / T1217 Browser Information — harvests cookies and browser data (Raccoon Stealer).T1552.001 / T1552.004 Credentials in Files / Private Keys — searches credential docs; exfiltrates code-signing certs.T1684.001 Impersonation — impersonates IT help desk to reset passwords/MFA.T1589 / T1589.001 Gather Victim Identity Info / Credentials — leverages prior-breach data to pass identity-verification challenges.T1087.002/.003/.004 Account Discovery (Domain/Email/Cloud) — enumerates AD, Entra ID groups and members.T1069.002 / T1069.003 Permission Groups Discovery — ADExplorer/ADRecon.ps1 for domain groups; Azure AD group membership.T1018 Remote System Discovery — maps vCenter/ESXi infrastructure.T1046 Network Service Discovery — RustScan port scanning.T1082 / T1016 / T1083 System/Network/File Discovery — OS fingerprinting, ping/nltest, hunting MFA docs, network diagrams, and credentials.T1580 / T1538 Cloud Infrastructure Discovery — enumerates AWS S3 and Systems Manager Inventory.T1213.002/.003/.005 Data from Information Repositories — SharePoint (VPN/MFA enrollment info), internal GitHub repos, Slack/Teams.T1021.001 RDP, T1021.004 SSH (incl. vCenter), T1021.007 Cloud Services (EC2/Azure).T1572 Protocol Tunneling — Teleport.sh, Chisel, ngrok, Pinggy, MobaXterm SSH tunnels.T1090 Proxy — proxy networks and rsocx reverse proxy to blend in.T1530 Data from Cloud Storage — OneDrive and cloud resources.T1114 / T1114.003 Email Collection / Forwarding Rule — searches Exchange for incident-response emails and forwards/redirects security alerts.T1074 Data Staged — consolidates stolen data into a central store.T1219.002) and tunnelers (T1572) double as resilient C2. ngrok (S0508) and Tor (S0183) appear in operations.T1578.002 Modify Cloud Compute Infrastructure — spins up attacker EC2/Azure VMs as staging/C2.T1041 Exfiltration Over C2 Channel — via Teleport.T1567.002 Exfiltration to Cloud Storage — MEGA, AWS S3; abuse of cloud DB platforms (e.g., Snowflake tenants). Rclone (S1040) used for cloud transfer.T1486 Data Encrypted for Impact — BlackCat/ALPHV and later DragonForce ransomware, notably against VMware ESXi.T1490 Inhibit System Recovery — stops Volume Shadow Copy service.T1006 Direct Volume Access — shadow-copies DC disks to grab NTDS.dit.T1657 Financial Theft — double-extortion: data theft + encryption with leak-site threats.Authorized use only: Execute the below exclusively within the documented rules of engagement and approved scope for this engagement; never SIM-swap real subscribers, social-engineer real third-party carriers/help desks outside scope, or deploy real ransomware against production data.
defense-evasion/social-engineering playbooks emulating help-desk vishing and SSO smishing (T1598.004, T1660). Use the phishing/portal-cloning capability to stand up an in-scope lookalike SSO page (T1583.001) and harvest test credentials/OTPs. Emulate MFA fatigue (T1621) and attacker-MFA-device registration (T1098.005, T1556.006) against authorized test identities rather than performing a real SIM swap (T1451 — emulate the OTP-interception outcome with a provisioned test number).T1087.004, T1069.003, T1580, T1538), add cloud credentials/roles (T1098.001, T1098.003), weaken Conditional Access / add trusted locations (T1556.009), and add a rogue federation trust (T1484.002) — all against the engagement's lab/test tenant.T1069.002, T1087.002), DCSync and NTDS via shadow copy (T1003.006, T1003.003, T1006), Mimikatz/LaZagne dumping (T1003). Use bash/PowerShell for Get-ADUser, nltest, and ping recon (T1059.001, T1016).T1021.001, T1021.004, T1047) and the c2/Sliver capability plus protocol tunneling (ngrok/Chisel-style, T1572, T1090) to mirror RMM-and-tunnel C2 (T1219.002). Deploy an approved RMM agent to a test host to replicate the signature T1204→T1219.002 chain.T1018, T1021.004) and group manipulation (T1098) — stop short of encryption; instead validate that backup/immutability controls would have blocked T1486/T1490.T1074) and exfiltrate to an in-scope cloud bucket via Rclone-style transfer (T1567.002) to test DLP/egress controls; emulate inbox-rule evasion (T1564.008, T1114.003) on a test mailbox.T1685), shadow-copy deletion (T1490), and encryption (T1486) detections — never real ransomware on production.T1598.004/T1684.001.T1621, T1451, T1556.006, T1098.005).T1556.009, T1484.002).T1583.001, T1660, T1598.001).T1219.002, T1572).T1486, T1490, T1003.x).4484f85
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.