Threat Intelligence / Actor / Scattered Spider

Scattered Spider

As of 2026-08-08, Scattered Spider is a threat actor tracked by Threadlinqs Intelligence across 13 threats spanning threat intel, ransomware, threat actor. Also known as Muddled Libra, 0ktapus, ShinyHunters, DEV-0971. ATT&CK coverage spans 138 techniques across 16 tactics in 13 of 13 tracked threats. Most-observed techniques: T1621 (Multi-Factor Authentication Request Generation), T1657 (Financial Theft), T1078 (Valid Accounts).

13 tracked threat(s) · Categories: THREAT_INTEL, RANSOMWARE, THREAT_ACTOR, DATA_BREACH, MALWARE, CAMPAIGN

Also known as: Muddled Libra, 0ktapus, ShinyHunters, DEV-0971, Octo Tempest, Oktapus, Roasted 0ktapus, Scatter Swine, Scattered Swine, Starfraud, Storm-0875, Storm-0971

ATT&CK techniques observed

138 techniques observed across 13 of 13 tracked threats · Credential Access (16), Discovery (16), Persistence (15), Defense Evasion (14), Collection (11), Initial Access (11)

Tracked threats

Related CVEs

2 CVEs referenced by tracked Scattered Spider activity

CVE-2021-35464, CVE-2015-2291

Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →

Threadlinqs Intelligence