🇺🇸Scattered Spider
🇺🇸 Scattered Spider is a tracked threat actor in the Clankerusecase corpus. Attributed to US. Primary motivation: Criminal. We map 26 detection use cases to this actor across 97 MITRE ATT&CK techniques, with 7 threat-intel articles citing them. Active in our corpus from 2025-12-11 to 2026-07-23.
crit 4high 2med 1
26Use cases
7Articles
97Techniques
21IOCs
Known aliases
Scattered Spider0ktapusUNC3944Octo TempestMuddled LibraRoasted 0ktapusStorm-0875
All other tracked techniques
T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1003.003 · NTDST1006 · Direct Volume AccessT1016 · System Network Configuration DiscoveryT1018 · Remote System DiscoveryT1021.001 · Remote Desktop ProtocolT1021.002 · SMB/Windows Admin SharesT1021.004 · SSHT1021.007 · Cloud ServicesT1027 · Obfuscated Files or InformationT1041 · Exfiltration Over C2 ChannelT1046 · Network Service DiscoveryT1047 · Windows Management InstrumentationT1053.005 · Scheduled TaskT1059.004 · Unix ShellT1059.005 · Visual BasicT1068 · Exploitation for Privilege EscalationT1069 · Permission Groups DiscoveryT1069.002 · Domain GroupsT1070.001 · T1070.001T1070.008 · Clear Mailbox DataT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1071.004 · DNST1074 · Data StagedT1078 · Valid AccountsT1078.001 · Default AccountsT1078.004 · Cloud AccountsT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1087 · Account DiscoveryT1087.002 · Domain AccountT1090 · ProxyT1098 · Account ManipulationT1098.003 · Additional Cloud RolesT1105 · Ingress Tool TransferT1110.003 · Password SprayingT1110.004 · Credential StuffingT1114 · Email CollectionT1114.003 · Email Forwarding RuleT1133 · External Remote ServicesT1136 · Create AccountT1195.002 · Compromise Software Supply ChainT1203 · Exploitation for Client ExecutionT1204 · User ExecutionT1204.001 · Malicious LinkT1204.002 · Malicious FileT1204.004 · Malicious Copy and PasteT1213.003 · Code RepositoriesT1213.005 · Messaging ApplicationsT1217 · Browser Information DiscoveryT1218 · System Binary Proxy ExecutionT1219 · Remote Access ToolsT1219.002 · Remote Desktop SoftwareT1484.002 · Trust ModificationT1486 · Data Encrypted for ImpactT1490 · Inhibit System RecoveryT1530 · Data from Cloud StorageT1538 · Cloud Service DashboardT1539 · Steal Web Session CookieT1543.002 · Systemd ServiceT1543.003 · Windows ServiceT1552.001 · Credentials In FilesT1552.004 · Private KeysT1553.002 · Code SigningT1555.003 · Credentials from Web BrowsersT1555.005 · Password ManagersT1556 · Modify Authentication ProcessT1556.006 · Multi-Factor AuthenticationT1556.009 · Conditional Access PoliciesT1562.001 · T1562.001T1564.008 · Email Hiding RulesT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1566.004 · Spearphishing VoiceT1567.002 · Exfiltration to Cloud StorageT1569.002 · Service ExecutionT1572 · Protocol TunnelingT1574.002 · T1574.002T1578.002 · Create Cloud InstanceT1580 · Cloud Infrastructure DiscoveryT1583.001 · DomainsT1585.001 · Social Media AccountsT1588.001 · MalwareT1588.002 · ToolT1589 · Gather Victim Identity InformationT1598 · Phishing for InformationT1598.003 · Spearphishing LinkT1598.004 · Spearphishing VoiceT1621 · Multi-Factor Authentication Request GenerationT1657 · Financial TheftT1684.001 · ImpersonationT1685 · Disable or Modify Tools
Detection use cases (26)
Scattered Spider (Octo Tempest) help-desk vishing: password reset → immediate MFA re-enrollment → login from new device Scattered Spider RMM & ngrok tunneling for hands-on-keyboard C2 (UNC3944 / Muddled Libra toolset) CL-STA-1114 (Void Blizzard) Zimbra espionage C2/exfil infrastructure contact Inbound HTML-attachment lure exploiting Zimbra XSS (CVE-2025-66376) Browser-initiated webmail data exfiltration to CL-STA-1114 C2 Unpatched Zimbra Collaboration exposed to CVE-2025-66376 (Void Blizzard target) Beaconing — periodic outbound to small set of destinations Network connections to article IPs / domains Asset exposure — vulnerability matches article CVE(s) Phishing-link click correlated to endpoint execution Email attachment opened from external sender Office app spawning script/LOLBin child process Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) PowerShell encoded / obfuscated command 1Password impossible-travel sign-in AI-Agent Server (PraisonAI/MCP) Spawns OS Shell or Recon LOLBin — Unauthenticated RCE Exploitation Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request Internet-Exposed AI Agent/LLM Service Spawns Shell or LOLBin After Inbound Connection Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution Language-runtime server (node/python/java) spawns OS shell shortly after inbound request — eval / sandbox-escape exploitation chain Linux LPE chain — anomalous algif_aead/esp4/esp6/rxrpc kernel-module load followed by same-user root transitionThreat-intel articles (7)
crit Russian Global Webmail Espionage · 2026-07-23
crit AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report · 2026-07-16
crit Inside the Modern SOC: The 72-Minute Race · 2026-06-15
Tracked indicators
Domains (9)
analyticemailmeter.com emailanalytics.com.ua istc-cloud.com mailnalysis.com synacorzimbra.nl zimbra-metadata.com zimbrasoft.com.ua zimbrastat.com zmailanalytics.comIP addresses (12)
104.248.134.194 185.86.79.95 193.233.202.17 193.238.152.66 194.156.103.193 216.252.238.104 216.252.238.18 216.252.238.64 37.120.247.228 45.86.230.112 64.226.124.190 77.110.122.137CVEs (10)
CVE-2023-27532 CVE-2024-37085 CVE-2024-55591 CVE-2025-32433 CVE-2025-33073 CVE-2025-55182 CVE-2025-59718 CVE-2025-59719 CVE-2025-66376 CVE-2025-7771