Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ Scattered Spider

🇺🇸Scattered Spider

🇺🇸 Scattered Spider is a tracked threat actor in the Clankerusecase corpus. Attributed to US. Primary motivation: Criminal. We map 24 detection use cases to this actor across 87 MITRE ATT&CK techniques, with 5 threat-intel articles citing them. Active in our corpus from 2025-12-11 to 2026-08-07.

crit 3high 1med 1
View full actor card → All threat actors MITRE ATT&CK group spec (G1015) ↗
24Use cases
5Articles
87Techniques
18IOCs

Known aliases

Scattered Spider0ktapusUNC3944Octo TempestMuddled LibraRoasted 0ktapusStorm-0875

Top techniques

All other tracked techniques

T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1003.003 · NTDST1006 · Direct Volume AccessT1016 · System Network Configuration DiscoveryT1018 · Remote System DiscoveryT1021.001 · Remote Desktop ProtocolT1021.002 · SMB/Windows Admin SharesT1021.004 · SSHT1021.007 · Cloud ServicesT1027 · Obfuscated Files or InformationT1041 · Exfiltration Over C2 ChannelT1059.001 · PowerShellT1059.004 · Unix ShellT1059.005 · Visual BasicT1068 · Exploitation for Privilege EscalationT1069 · Permission Groups DiscoveryT1069.002 · Domain GroupsT1070.008 · Clear Mailbox DataT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1071.004 · DNST1074 · Data StagedT1078 · Valid AccountsT1078.004 · Cloud AccountsT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1087 · Account DiscoveryT1087.002 · Domain AccountT1090 · ProxyT1098 · Account ManipulationT1098.003 · Additional Cloud RolesT1105 · Ingress Tool TransferT1114 · Email CollectionT1114.003 · Email Forwarding RuleT1133 · External Remote ServicesT1136 · Create AccountT1190 · Exploit Public-Facing ApplicationT1195.002 · Compromise Software Supply ChainT1203 · Exploitation for Client ExecutionT1204 · User ExecutionT1204.002 · Malicious FileT1204.004 · Malicious Copy and PasteT1213.003 · Code RepositoriesT1213.005 · Messaging ApplicationsT1217 · Browser Information DiscoveryT1218 · System Binary Proxy ExecutionT1219 · Remote Access ToolsT1219.002 · Remote Desktop SoftwareT1484.002 · Trust ModificationT1486 · Data Encrypted for ImpactT1490 · Inhibit System RecoveryT1530 · Data from Cloud StorageT1538 · Cloud Service DashboardT1539 · Steal Web Session CookieT1543.002 · Systemd ServiceT1552.001 · Credentials In FilesT1552.004 · Private KeysT1553.002 · Code SigningT1555.003 · Credentials from Web BrowsersT1555.005 · Password ManagersT1556.006 · Multi-Factor AuthenticationT1556.009 · Conditional Access PoliciesT1564.008 · Email Hiding RulesT1566.001 · Spearphishing AttachmentT1566.004 · Spearphishing VoiceT1567.002 · Exfiltration to Cloud StorageT1569.002 · Service ExecutionT1572 · Protocol TunnelingT1574.002 · T1574.002T1578.002 · Create Cloud InstanceT1580 · Cloud Infrastructure DiscoveryT1583.001 · DomainsT1585.001 · Social Media AccountsT1588.001 · MalwareT1588.002 · ToolT1589 · Gather Victim Identity InformationT1598 · Phishing for InformationT1598.003 · Spearphishing LinkT1598.004 · Spearphishing VoiceT1621 · Multi-Factor Authentication Request GenerationT1657 · Financial TheftT1684.001 · ImpersonationT1685 · Disable or Modify Tools

Detection use cases (24)

Infostealer — non-browser process accessing browser cookie/login DBs Internal Phishing-link click correlated to endpoint execution Internal Email attachment opened from external sender Internal Office app spawning script/LOLBin child process Internal MFA fatigue / push-bombing Internal Ransomware-style mass file rename / extension change Internal LSASS process access / dump (credential theft) Internal Remote service execution — PsExec / SMB lateral movement Internal RMM tool installed by non-IT user — remote-access utility for hands-on-keyboard Internal Phishing-link click correlated to endpoint execution Internal Email attachment opened from external sender Internal Office app spawning script/LOLBin child process Internal 1Password impossible-travel sign-in MITRE match AI-Agent Server (PraisonAI/MCP) Spawns OS Shell or Recon LOLBin — Unauthenticated RCE Exploitation MITRE match Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) MITRE match Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes MITRE match Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN MITRE match Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) MITRE match Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request MITRE match Internet-Exposed AI Agent/LLM Service Spawns Shell or LOLBin After Inbound Connection MITRE match Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) MITRE match Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution MITRE match Language-runtime server (node/python/java) spawns OS shell shortly after inbound request — eval / sandbox-escape exploitation chain MITRE match Linux LPE chain — anomalous algif_aead/esp4/esp6/rxrpc kernel-module load followed by same-user root transition MITRE match

Threat-intel articles (5)

Tracked indicators

Domains (9)

analyticemailmeter.com emailanalytics.com.ua istc-cloud.com mailnalysis.com synacorzimbra.nl zimbra-metadata.com zimbrasoft.com.ua zimbrastat.com zmailanalytics.com

IP addresses (9)

104.248.134.194 185.86.79.95 193.238.152.66 194.156.103.193 216.252.238.104 216.252.238.18 216.252.238.64 37.120.247.228 64.226.124.190

CVEs (1)

CVE-2025-66376