Scattered Spider
A financially motivated cluster known for identity attacks, helpdesk manipulation, SIM swapping, and cloud-focused intrusion.
Brief overview
Scattered Spider often begins with research on employees and high-pressure social engineering against users or helpdesks. After obtaining credentials, operators have created accounts, changed MFA methods, used legitimate remote-management tooling, and explored cloud environments. The name covers a changing cluster, so defenders should prioritize repeatable behavior over a fixed list of infrastructure.
Behavioral indicators
- Unexpected password resets or MFA enrollment following a helpdesk interaction
- New cloud identities, privilege changes, or remote-access tools without an approved change
- Phishing domains imitating corporate identity, SSO, or support portals
Defender next steps
- Require phishing-resistant MFA for privileged and remote access.
- Use out-of-band identity verification for password resets and MFA recovery.
- Alert on new accounts, MFA changes, SaaS administrator actions, and first-seen remote tools.
MITRE ATT&CK mapping