Scattered Spider, also known as 0ktapus, Starfraud, UNC3944, Scatter Swine, Octo Tempest, and Muddled Libra, is a group of threat actors that are adept at using social engineering attacks, phishing, multi-factor authentication (MFA) bombing (targeted MFA fatigue), and SIM swapping to gain initial network access on large organizations. Ongoing outages at British retail giant Marks & Spencer are caused by a ransomware attack believed to be conducted by a hacking collective known as "Scattered Spider" BleepingComputer has learned from multiple sources. Researchers commonly associate attacks with the Scattered Spider group based on specific indicators of compromise, including credential-stealing phishing attacks targeting SSO platforms, social engineering attacks impersonating IT help desktop, and other tactics. While the media and researchers commonly refer to Scattered Spider as a cohesive gang, they are actually a network of individuals, with different threat actors participating in each attack. The group escalated its attacks in September 2023 when they breached MGM Resorts utilizing a social engineering attack impersonating an employee when calling the company's IT help desk.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Mon, 28 Apr 2025 20:30:15 +0000