CtrlK
BlogDocsLog inGet started
Tessl Logo

scattered-spider

Adversary-emulation profile for Scattered Spider (UNC3944/Octo Tempest), a financially motivated social-engineering-led intrusion group, mapped to ATT&CK G1015 and Decepticon tooling.

49

Quality

53%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/scattered-spider/SKILL.md
SKILL.md
Quality
Evals
Security

Scattered Spider (UNC3944, Octo Tempest, Muddled Libra, Star Fraud) — Adversary Emulation Profile

Scattered Spider (MITRE ATT&CK G1015) is a financially motivated, predominantly native English-speaking cybercriminal collective active since at least 2022 and widely linked to the loosely affiliated "The Com" social network. The group is exceptional not for novel malware but for aggressive, high-tempo social engineering of human identity processes: it phones and SMS-phishes help desks and employees, impersonates IT staff, bypasses MFA (push bombing, SIM swapping, attacker-registered tokens), and rapidly pivots into cloud identity (Microsoft Entra ID, Okta, AWS, Azure) and virtualization (VMware ESXi/vCenter) before staging data theft and ransomware. It began with the 2022 "0ktapus" Okta-credential phishing wave, escalated to the high-profile 2023 MGM Resorts and Caesars Entertainment intrusions, and through 2024–2025 operated as an affiliate of multiple ransomware-as-a-service brands (BlackCat/ALPHV, RansomHub, Qilin, DragonForce), hitting retail, insurance, and aviation. This profile teaches Decepticon to emulate G1015's signature identity-centric TTPs inside an authorized engagement and helps the blue cell anticipate detection.

Attribution & motivation

  • Sponsor / nation: Non-state, criminal. Members are assessed to be primarily young, native English speakers based in the US and UK, affiliated with the broader "The Com" cybercrime community. Not a nation-state actor; multiple arrests and a 2025 US extradition have been reported (per Krebs on Security / Infosecurity Magazine).
  • Motivation: Primarily financial — credential theft, SIM-swap fraud / crypto theft, data extortion, and ransomware (T1657 Financial Theft). There is no credible espionage, destructive-only, or influence mandate; destruction (encryption) is in service of extortion.
  • Confidence: High confidence the cluster tracked as Scattered Spider = UNC3944 (Mandiant/Google) = Octo Tempest / Storm-0875 (Microsoft) = Muddled Libra (Palo Alto Unit 42) = Roasted 0ktapus = Scatter Swine = Star Fraud. Note these vendor clusters overlap but are not byte-for-byte identical; treat as a fluid affiliate community rather than a fixed roster.

Targeting

  • Sectors: Initially telecom, BPO/outsourcing, and CRM/SaaS providers (for SIM-swap and downstream access); from 2023 expanded to hospitality & gaming (casinos), retail, technology/MSP, manufacturing, and financial services / insurance; in mid-2025, aviation.
  • Regions: Primarily English-speaking targets — United States, United Kingdom, Canada, Australia — with reporting of expansion toward Singapore and India.
  • Victim profile: Large enterprises with large outsourced or tiered IT help desks, heavy reliance on SSO/MFA (Okta, Microsoft Entra ID), significant cloud/SaaS footprint, and VMware-virtualized data centers. The human help desk and identity-recovery workflow is the deliberately chosen weak point.

Notable campaigns

  • Aug 2022 — "0ktapus" / Roasted 0ktapus: SMS smishing campaign harvesting Okta credentials and OTPs via ~169 lookalike domains; ~130 organizations compromised, including downstream intrusions at Twilio, Cloudflare (blocked), Mailchimp, DoorDash, and LastPass. (Group-IB, "Roasting 0ktapus.")
  • Sep 2023 — MGM Resorts & Caesars Entertainment: Help-desk vishing (an employee impersonation reportedly seeded from LinkedIn) granted access; MGM suffered major operational disruption, Caesars reportedly paid a ransom. BlackCat/ALPHV ransomware was associated. (Reuters/CyberScoop reporting; CISA AA23-320A.)
  • Nov 16, 2023 — CISA/FBI Joint Advisory AA23-320A first published, codifying the group's TTPs. (CISA.)
  • 2024 — RaaS affiliate shift: Following ALPHV's collapse, the group operated with RansomHub and Qilin affiliates.
  • Apr–May 2025 — UK retail wave: Marks & Spencer (initial access reportedly Feb 2025), Co-op, and Harrods; M&S disruption estimated in the hundreds of millions of GBP, with DragonForce ransomware deployed against ESXi. UK arrests of four suspects followed. (The Hacker News; Mandiant/Google.)
  • Jun 2025 — US insurance sector: Reported intrusions including Philadelphia Insurance Companies and Erie Insurance. (Push Security; Claranet.)
  • Late Jun–Jul 2025 — Aviation: FBI warned of expansion to airlines; incidents reported at Hawaiian Airlines, WestJet, and Qantas (third-party contact-center platform). (CSO Online.)
  • Jul 29, 2025 — AA23-320A updated by FBI/CISA + international partners (RCMP, ASD's ACSC, AFP, CCCS, NCSC-UK) with TTPs current to June 2025 and confirmation of DragonForce deployment. (IC3/CISA.)

TTPs by ATT&CK tactic

Resource Development

  • T1583.001 Acquire Infrastructure: Domains — registers lookalike/SSO-spoofing domains (e.g. victim-helpdesk[.]com, victim-sso[.]com).
  • T1585.001 Establish Accounts: Social Media — builds fake personas; uses LinkedIn for target profiling.
  • T1588.001 / T1588.002 Obtain Capabilities (Malware/Tools) — acquires info-stealers, RATs, ransomware, and offensive tools (RustScan, LinPEAS, aws_consoler, rsocx, Level RMM).
  • T1102 Web Service — stages/downloads tooling from file.io, GitHub, paste.ee.

Initial Access

  • T1598.004 / T1566.004 Spearphishing Voice (vishing) — calls help desks/employees impersonating IT to trigger password and MFA resets; signature technique.
  • T1660 / T1598.003 Phishing (mobile / spearphishing link) — SMS smishing to credential-harvesting portals mimicking SSO.
  • T1598.001 Spearphishing Service — Telegram/Teams messages impersonating IT personnel.
  • T1451 SIM-Card Swap — social-engineers carriers to port victim numbers and intercept SMS OTPs.
  • T1190 Exploit Public-Facing Application — opportunistic (e.g., CVE-2021-35464 in ForgeRock OpenAM).
  • T1133 External Remote Services — abuses VPNs, Citrix, and remote-access tooling for entry.
  • T1078 / T1078.004 Valid Accounts (incl. Cloud) — logs in with socially-engineered credentials; compromised Entra ID/Azure accounts.
  • T1199 Trusted Relationship — pivots through MSPs, BPOs, and third-party contact-center platforms.
  • T1621 MFA Request Generation — push-bombing / MFA-fatigue until a victim approves.

Execution

  • T1204 User Execution — directs impersonated victims to install RMM agents.
  • T1219.002 Remote Desktop Software — deploys TeamViewer, AnyDesk, LogMeIn, ConnectWise, ngrok-based access.
  • T1059.001 PowerShell — e.g., Get-ADUser and recon scripting.
  • T1059.004 Unix Shell — installs Teleport and tooling on Linux/ESXi.
  • T1047 Windows Management Instrumentation — via Impacket for remote execution/lateral movement.

Persistence

  • T1098.005 Device Registration — registers attacker MFA devices/endpoints for durable access through VPN.
  • T1136 Create Account — creates new identities in the victim tenant/domain.
  • T1098 / T1098.001 / T1098.003 Account Manipulation — adds accounts to privileged groups (e.g., ESX Admins), adds cloud credentials, assigns admin roles.
  • T1556.006 Modify Authentication Process: MFA — registers own MFA tokens post-compromise.
  • T1484.002 Domain Trust Modification — adds a rogue federated IdP to the SSO tenant for backdoor authentication.
  • T1543.002 / T1547.005 Systemd Service / SSP — Teleport persistence on Linux; Mimikatz SSP.

Privilege Escalation

  • T1556.009 Conditional Access Policies — adds trusted locations / weakens CA to bypass MFA for controlled accounts.
  • T1068 Exploitation for Privilege Escalation — has deployed a malicious kernel driver (BYOVD via CVE-2015-2291).
  • T1548.002 Bypass UAC — via tooling (BlackCat, WarzoneRAT).

Defense Evasion

  • T1685 Disable or Modify Tools / T1562 Impair Defenses — uninstalls/disables EDR and security agents.
  • T1564.008 Email Hiding Rules / T1070.008 Clear Mailbox Data — auto-deletes vendor security alert emails; deletes traces of its own account activity.
  • T1553.002 Code Signing — abuses self-signed and stolen certificates (e.g., NVIDIA, Global Software LLC).
  • T1027 Obfuscated Files / T1134 Access Token Manipulation — malware-delivered obfuscation and token abuse.

Credential Access

  • T1003 / T1003.003 / T1003.006 OS Credential Dumping (Mimikatz, LaZagne), NTDS extraction via shadow copies, and DCSync.
  • T1555.005 Password Managers — hunts HashiCorp Vault and PAM solutions.
  • T1539 Steal Web Session Cookie / T1217 Browser Information — harvests cookies and browser data (Raccoon Stealer).
  • T1552.001 / T1552.004 Credentials in Files / Private Keys — searches credential docs; exfiltrates code-signing certs.
  • T1684.001 Impersonation — impersonates IT help desk to reset passwords/MFA.
  • T1589 / T1589.001 Gather Victim Identity Info / Credentials — leverages prior-breach data to pass identity-verification challenges.

Discovery

  • T1087.002/.003/.004 Account Discovery (Domain/Email/Cloud) — enumerates AD, Entra ID groups and members.
  • T1069.002 / T1069.003 Permission Groups Discovery — ADExplorer/ADRecon.ps1 for domain groups; Azure AD group membership.
  • T1018 Remote System Discovery — maps vCenter/ESXi infrastructure.
  • T1046 Network Service Discovery — RustScan port scanning.
  • T1082 / T1016 / T1083 System/Network/File Discovery — OS fingerprinting, ping/nltest, hunting MFA docs, network diagrams, and credentials.
  • T1580 / T1538 Cloud Infrastructure Discovery — enumerates AWS S3 and Systems Manager Inventory.
  • T1213.002/.003/.005 Data from Information Repositories — SharePoint (VPN/MFA enrollment info), internal GitHub repos, Slack/Teams.

Lateral Movement

  • T1021.001 RDP, T1021.004 SSH (incl. vCenter), T1021.007 Cloud Services (EC2/Azure).
  • T1572 Protocol Tunneling — Teleport.sh, Chisel, ngrok, Pinggy, MobaXterm SSH tunnels.
  • T1090 Proxy — proxy networks and rsocx reverse proxy to blend in.

Collection

  • T1530 Data from Cloud Storage — OneDrive and cloud resources.
  • T1114 / T1114.003 Email Collection / Forwarding Rule — searches Exchange for incident-response emails and forwards/redirects security alerts.
  • T1074 Data Staged — consolidates stolen data into a central store.

Command & Control

  • RMM tools (T1219.002) and tunnelers (T1572) double as resilient C2. ngrok (S0508) and Tor (S0183) appear in operations.
  • T1578.002 Modify Cloud Compute Infrastructure — spins up attacker EC2/Azure VMs as staging/C2.

Exfiltration

  • T1041 Exfiltration Over C2 Channel — via Teleport.
  • T1567.002 Exfiltration to Cloud Storage — MEGA, AWS S3; abuse of cloud DB platforms (e.g., Snowflake tenants). Rclone (S1040) used for cloud transfer.

Impact

  • T1486 Data Encrypted for Impact — BlackCat/ALPHV and later DragonForce ransomware, notably against VMware ESXi.
  • T1490 Inhibit System Recovery — stops Volume Shadow Copy service.
  • T1006 Direct Volume Access — shadow-copies DC disks to grab NTDS.dit.
  • T1657 Financial Theft — double-extortion: data theft + encryption with leak-site threats.

Signature tooling & malware

  • Ransomware (RaaS affiliate, not owned): BlackCat/ALPHV (S1068), DragonForce, RansomHub, Qilin — deployed especially against ESXi.
  • Credential tooling (public): Mimikatz (S0002), LaZagne (S0349), Impacket (S0357), Raccoon Stealer (S1148).
  • Remote access / RMM (legitimate, abused): TeamViewer, AnyDesk, LogMeIn, ConnectWise ScreenConnect (S0591), Level RMM, Splashtop, Pulseway.
  • Tunneling / C2: ngrok (S0508), Chisel, Teleport.sh, Pinggy, rsocx, MobaXterm, Tor (S0183).
  • Recon / cloud: RustScan, ADExplorer, ADRecon.ps1, SharpHound, LinPEAS, aws_consoler.
  • Exfil: Rclone (S1040), MEGA client.
  • RATs / drivers: WarzoneRAT (S0670); BYOVD kernel driver (CVE-2015-2291).
  • Hallmark: minimal custom malware — the group weaponizes legitimate admin/RMM software and identity systems, making it hard to catch with signature-based detection.

Emulation guidance (Decepticon)

Authorized use only: Execute the below exclusively within the documented rules of engagement and approved scope for this engagement; never SIM-swap real subscribers, social-engineer real third-party carriers/help desks outside scope, or deploy real ransomware against production data.

  • Initial access via identity, not exploits. Lead with defense-evasion/social-engineering playbooks emulating help-desk vishing and SSO smishing (T1598.004, T1660). Use the phishing/portal-cloning capability to stand up an in-scope lookalike SSO page (T1583.001) and harvest test credentials/OTPs. Emulate MFA fatigue (T1621) and attacker-MFA-device registration (T1098.005, T1556.006) against authorized test identities rather than performing a real SIM swap (T1451 — emulate the OTP-interception outcome with a provisioned test number).
  • Cloud/identity pivot. Use the cloud skills (Azure/Entra + AWS) to emulate G1015's identity tradecraft: enumerate Entra ID/AWS accounts and groups (T1087.004, T1069.003, T1580, T1538), add cloud credentials/roles (T1098.001, T1098.003), weaken Conditional Access / add trusted locations (T1556.009), and add a rogue federation trust (T1484.002) — all against the engagement's lab/test tenant.
  • AD operations. Drive the AD skills: ADExplorer/SharpHound-style enumeration (T1069.002, T1087.002), DCSync and NTDS via shadow copy (T1003.006, T1003.003, T1006), Mimikatz/LaZagne dumping (T1003). Use bash/PowerShell for Get-ADUser, nltest, and ping recon (T1059.001, T1016).
  • Lateral movement & C2. Use the lateral-movement skill for RDP/SSH/WMI (T1021.001, T1021.004, T1047) and the c2/Sliver capability plus protocol tunneling (ngrok/Chisel-style, T1572, T1090) to mirror RMM-and-tunnel C2 (T1219.002). Deploy an approved RMM agent to a test host to replicate the signature T1204T1219.002 chain.
  • Virtualization target. Where the lab includes VMware, emulate vCenter/ESXi enumeration and SSH access (T1018, T1021.004) and group manipulation (T1098) — stop short of encryption; instead validate that backup/immutability controls would have blocked T1486/T1490.
  • Collection & exfil simulation. Stage benign canary data (T1074) and exfiltrate to an in-scope cloud bucket via Rclone-style transfer (T1567.002) to test DLP/egress controls; emulate inbox-rule evasion (T1564.008, T1114.003) on a test mailbox.
  • Impact (simulated): For ransomware emulation, use a benign/inert payload or a detonation-safe simulator against test ESXi/hosts to exercise EDR-disable (T1685), shadow-copy deletion (T1490), and encryption (T1486) detections — never real ransomware on production.

Detection & defense

  • Identity verification at the help desk: require strong, out-of-band, on-camera or in-person verification before any password/MFA reset; never rely on DOB/last-4-SSN; temporarily disable self-service MFA resets during active threats. Directly counters T1598.004/T1684.001.
  • Phishing-resistant MFA: remove SMS/voice/email factors; deploy FIDO2/number-matching; restrict MFA registration to trusted IPs/compliant devices; alert on the same MFA method registered across multiple users (counters T1621, T1451, T1556.006, T1098.005).
  • Entra ID / SSO monitoring: alert on changes to Conditional Access Policies, Trusted Named Locations, and federation/domain config; verify all federated domains (counters T1556.009, T1484.002).
  • Detect lookalike domains & smishing portals: continuous brand/typosquat domain monitoring; user training to reject MFA push-bombing and report IT-impersonation SMS/Teams messages (counters T1583.001, T1660, T1598.001).
  • RMM control: allow-list approved remote-access software; alert on TeamViewer/AnyDesk/ScreenConnect/ngrok install or execution and outbound to tunneling services (counters T1219.002, T1572).
  • Teams/collaboration detection: alert on external-tenant chats with display names containing "help"/"helpdesk" (Mandiant-provided KQL/SecOps rules).
  • Recon tooling: alert on ADRecon, ADExplorer, SharpHound, RustScan execution; lock down docs containing VPN/MFA-enrollment/network-diagram info (counters discovery cluster).
  • Identity store segregation & Tier-0: decouple AD from cloud/virtualization/backup identity; local, vault-excluded, MFA-enforced root accounts for ESXi/vCenter; enable ESXi lockdown mode; immutable, network-isolated backups (counters T1486, T1490, T1003.x).
  • Egress restriction & session monitoring: restrict outbound from DCs/TSI servers; block Tor exit nodes and VPS ranges; alert on impossible-travel, proxy/VPN logins, and token replay (counters C2/exfil cluster).

Sources

Repository
PurpleAILAB/Decepticon
Last updated
First committed

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.