Threat Intelligence / Actor / Scattered Spider
Scattered Spider
As of 2026-08-08, Scattered Spider is a threat actor tracked by Threadlinqs Intelligence across 13 threats spanning threat intel, ransomware, threat actor. Also known as Muddled Libra, 0ktapus, ShinyHunters, DEV-0971. ATT&CK coverage spans 138 techniques across 16 tactics in 13 of 13 tracked threats. Most-observed techniques: T1621 (Multi-Factor Authentication Request Generation), T1657 (Financial Theft), T1078 (Valid Accounts).
Also known as: Muddled Libra, 0ktapus, ShinyHunters, DEV-0971, Octo Tempest, Oktapus, Roasted 0ktapus, Scatter Swine, Scattered Swine, Starfraud, Storm-0875, Storm-0971
ATT&CK techniques observed
- T1621 Multi-Factor Authentication Request Generation — Credential Access — observed in 11 of 13 tracked threats
- T1657 Financial Theft — Impact — observed in 11 of 13 tracked threats
- T1078 Valid Accounts — Defense Evasion — observed in 10 of 13 tracked threats
- T1098 Account Manipulation — Persistence — observed in 8 of 13 tracked threats
- T1199 Trusted Relationship — Initial Access — observed in 8 of 13 tracked threats
- T1213 Data from Information Repositories — Collection — observed in 8 of 13 tracked threats
- T1486 Data Encrypted for Impact — Impact — observed in 8 of 13 tracked threats
- T1530 Data from Cloud Storage — Collection — observed in 8 of 13 tracked threats
- T1566 Phishing — Initial Access — observed in 8 of 13 tracked threats
- T1567 Exfiltration Over Web Service — Exfiltration — observed in 8 of 13 tracked threats
- T1589 Gather Victim Identity Information — Reconnaissance — observed in 8 of 13 tracked threats
- T1204 User Execution — Execution — observed in 7 of 13 tracked threats
- T1528 Steal Application Access Token — Credential Access — observed in 7 of 13 tracked threats
- T1552 Unsecured Credentials — Credential Access — observed in 7 of 13 tracked threats
- T1087 Account Discovery — Discovery — observed in 6 of 13 tracked threats
Tracked threats
- Unit 42: Identity Compromise Is the Primary Attack Vector in Nearly 90% of Incidents — HIGH
- DragonForce Ransomware: Vishing-Driven Help Desk Social Engineering Against UK Retailers (M&S, Co-op, Harrods) — HIGH
- Two Scattered Spider Leaders Jailed for £29M Transport for London (TfL) Cyberattack — HIGH
- Check Point 2026 AI Security Report: Autonomous AI-Driven Exploitation, CLAUDE.md Jailbreaking, and Generative Identity Fraud Fuel Scattered Spider / ShinyHunters Campaigns — HIGH
- Scattered Spider (G1015): RMM-Based Persistence and Social-Engineering Intrusion Tradecraft — HIGH
- Infinite Campus Salesforce Breach by ShinyHunters / UNC6040 — 137,100 K-12 School Staff Accounts Exfiltrated and Extorted — HIGH
- BYOVD EDR Killer Tooling — Ransomware Groups Weaponizing Signed Kernel Drivers to Blind Endpoint Detection — HIGH
- ShinyHunters Leaks 5.1 Million Panera Bread Customer Records — HIGH
- ShinyHunters Evolves TTPs: Vishing and Login Harvesting for SSO/MFA Bypass — HIGH
- ShinyHunters-Branded Extortion Campaign Expands with Vishing & SSO Attacks — HIGH
- SLSH Extortion Group - Swatting and Executive Harassment Tactics — HIGH
- ShinyHunters Extortion Campaign - Evolved Vishing and SSO Credential Theft — HIGH
- ShinyHunters SSO Vishing Campaign - Cloud Data Theft via Social Engineering — CRITICAL
Related CVEs
Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →