Scattered Spider (G1015): RMM-Based Persistence and Social-Engineering Intrusion Tradecraft — Threadlinqs Intelligence
As of 2026-07-14, Scattered Spider (G1015): RMM-Based Persistence and Social-Engineering Intrusion Tradecraft is a high-severity threat actor threat attributed to Scattered Spider, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-1333 · Severity: HIGH · Status: ACTIVE · Category: THREAT_ACTOR
Attribution: Scattered Spider · FINANCIAL
Scattered Spider (MITRE ATT&CK G1015, aka UNC3944 / Octo Tempest / Roasted 0ktapus / Storm-0875 / Scatter Swine) is a native-English-speaking eCrime group active since at least May 2022 that bypasses
Scattered Spider is a financially motivated, native-English-speaking cybercriminal collective tracked by MITRE ATT&CK as G1015 and across the industry as UNC3944, Octo Tempest, Roasted 0ktapus, Storm-0875, and Scatter Swine. Active since at least May 2022, the group's defining tradecraft is voice-based social engineering: operators call an organization's IT help desk or call an employee directly while impersonating IT/help-desk staff, using pretexting built from OSINT (LinkedIn, corporate directories, breach data) to sound convincing to native English speakers. The pretext is used to request password resets, new MFA device enrollment, or approval of a push/OTP prompt, effectively bypassing MFA without exploiting a technical flaw. Where impersonation alone does not succeed, the group escalates to MFA push-bombing (MFA fatigue, T1621) or SIM-swapping the victim's phone number to intercept SMS OTPs and voice calls.
Once initial access to an identity provider (commonly Okta) or VPN/remote-access portal is obtained, Scattered Spider registers rogue MFA devices, modifies conditional-access and identity federation policies, and creates new cloud roles/service principals for durable access (T1098, Account Manipulation). The group is notorious for large-scale phishing infrastructure supporting its social engineering: hundreds of registered lookalike domains following predictable naming patterns such as victimname-sso[.]com, victimname-servicedesk[.]com, victimname-okta[.]com, victimname-mfa[.]help, and (since Q1 2025) subdomain-based variants like sso.victimname[.]com to evade hyphenated-domain detections, frequently paired with the Evilginx adversary-in-the-middle phishing framework to relay live MFA challenges and steal session tokens.
Once inside, the group performs extensive discovery: enumerating privileged accounts and groups (T1069, T1087), mapping Active Directory with SysInternals ADExplorer, and mapping cloud tenancy (Azure AD/Entra ID, AWS, GCP) via native cloud APIs and console access (T1580). Credential harvesting relies heavily on Mimikatz and LaZagne for OS credential dumping (T1003, including NTDS.dit extraction and DCSync) and on Credentials from Password Stores (T1555.005) targeting password managers and browser vaults. For lateral movement and remote access the group installs legitimate commercial RMM tools -- AnyDesk, TeamViewer, ConnectWise ScreenConnect, LogMeIn, and TightVNC/VNC -- using silent/unattended installer switches so the software runs without a visible UI, blending into normal IT operations and evading detections keyed on file hashes rather than installation behavior. For network pivoting the group tunnels through firewalls with the open-source SOCKS/reverse-proxy utility Chisel, ngrok, and the Go-based Teleport agent, and has used Brute Ratel C4 and Cobalt Strike as post-exploitation C2 frameworks, alongside Impacket for SMB/WMI-based lateral movement.
A hallmark defense-evasion capability is the POORTRY/STONESTOP malicious driver toolkit, first observed deployed by UNC3944 as early as August 2022 and documented by Mandiant/Google Cloud TAG and Microsoft. STONESTOP is a Windows userland loader/orchestrator that installs and directs the POORTRY kernel-mode driver, which is used to terminate security and EDR processes with kernel privileges (Impair Defenses / T1562.001). Multiple POORTRY samples were legitimately code-signed via abused Microsoft Windows Hardware Compatibility Publisher (attestation-signing) certificates obtained by threat actors who compromised or purchased access to legitimate Microsoft Partner Center developer accounts; Microsoft suspended the abused partner accounts after a signing attempt was caught on 29 September 2022.
For data theft, the group exfiltrates over legitimate cloud storage and file-transfer services -- MEGA, Snowflake, AWS S3 -- (T1567.002, T1530) and pulls data from SharePoint and internal code repositories (T1213). Rclone is a commonly used exfiltration utility.
Weaknesses (CWE)
CWE-287, CWE-295, CWE-494
Target sectors: telecoms, technology, businessprocessoutsourcing, gaming, hospitality, retail, managedserviceproviders, manufacturing, financialservices, insurance, aviation
Target regions: North America, Europe, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_ACTOR, HIGH, threat intelligence, cybersecurity, CVE-2021-35464, T1589, T1566.004, T1190, T1133, T1199, T1059.001, T1098, T1133, T1098.003, T1078