🇺🇸Scattered Spider
🇺🇸 Scattered Spider is a tracked threat actor in the Clankerusecase corpus. Attributed to US. Primary motivation: Criminal. We map 24 detection use cases to this actor across 87 MITRE ATT&CK techniques, with 5 threat-intel articles citing them. Active in our corpus from 2025-12-11 to 2026-08-07.
crit 3high 1med 1
24Use cases
5Articles
87Techniques
18IOCs
Known aliases
Scattered Spider0ktapusUNC3944Octo TempestMuddled LibraRoasted 0ktapusStorm-0875
All other tracked techniques
T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1003.003 · NTDST1006 · Direct Volume AccessT1016 · System Network Configuration DiscoveryT1018 · Remote System DiscoveryT1021.001 · Remote Desktop ProtocolT1021.002 · SMB/Windows Admin SharesT1021.004 · SSHT1021.007 · Cloud ServicesT1027 · Obfuscated Files or InformationT1041 · Exfiltration Over C2 ChannelT1059.001 · PowerShellT1059.004 · Unix ShellT1059.005 · Visual BasicT1068 · Exploitation for Privilege EscalationT1069 · Permission Groups DiscoveryT1069.002 · Domain GroupsT1070.008 · Clear Mailbox DataT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1071.004 · DNST1074 · Data StagedT1078 · Valid AccountsT1078.004 · Cloud AccountsT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1087 · Account DiscoveryT1087.002 · Domain AccountT1090 · ProxyT1098 · Account ManipulationT1098.003 · Additional Cloud RolesT1105 · Ingress Tool TransferT1114 · Email CollectionT1114.003 · Email Forwarding RuleT1133 · External Remote ServicesT1136 · Create AccountT1190 · Exploit Public-Facing ApplicationT1195.002 · Compromise Software Supply ChainT1203 · Exploitation for Client ExecutionT1204 · User ExecutionT1204.002 · Malicious FileT1204.004 · Malicious Copy and PasteT1213.003 · Code RepositoriesT1213.005 · Messaging ApplicationsT1217 · Browser Information DiscoveryT1218 · System Binary Proxy ExecutionT1219 · Remote Access ToolsT1219.002 · Remote Desktop SoftwareT1484.002 · Trust ModificationT1486 · Data Encrypted for ImpactT1490 · Inhibit System RecoveryT1530 · Data from Cloud StorageT1538 · Cloud Service DashboardT1539 · Steal Web Session CookieT1543.002 · Systemd ServiceT1552.001 · Credentials In FilesT1552.004 · Private KeysT1553.002 · Code SigningT1555.003 · Credentials from Web BrowsersT1555.005 · Password ManagersT1556.006 · Multi-Factor AuthenticationT1556.009 · Conditional Access PoliciesT1564.008 · Email Hiding RulesT1566.001 · Spearphishing AttachmentT1566.004 · Spearphishing VoiceT1567.002 · Exfiltration to Cloud StorageT1569.002 · Service ExecutionT1572 · Protocol TunnelingT1574.002 · T1574.002T1578.002 · Create Cloud InstanceT1580 · Cloud Infrastructure DiscoveryT1583.001 · DomainsT1585.001 · Social Media AccountsT1588.001 · MalwareT1588.002 · ToolT1589 · Gather Victim Identity InformationT1598 · Phishing for InformationT1598.003 · Spearphishing LinkT1598.004 · Spearphishing VoiceT1621 · Multi-Factor Authentication Request GenerationT1657 · Financial TheftT1684.001 · ImpersonationT1685 · Disable or Modify Tools
Detection use cases (24)
Infostealer — non-browser process accessing browser cookie/login DBs Phishing-link click correlated to endpoint execution Email attachment opened from external sender Office app spawning script/LOLBin child process MFA fatigue / push-bombing Ransomware-style mass file rename / extension change LSASS process access / dump (credential theft) Remote service execution — PsExec / SMB lateral movement RMM tool installed by non-IT user — remote-access utility for hands-on-keyboard Phishing-link click correlated to endpoint execution Email attachment opened from external sender Office app spawning script/LOLBin child process 1Password impossible-travel sign-in AI-Agent Server (PraisonAI/MCP) Spawns OS Shell or Recon LOLBin — Unauthenticated RCE Exploitation Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request Internet-Exposed AI Agent/LLM Service Spawns Shell or LOLBin After Inbound Connection Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution Language-runtime server (node/python/java) spawns OS shell shortly after inbound request — eval / sandbox-escape exploitation chain Linux LPE chain — anomalous algif_aead/esp4/esp6/rxrpc kernel-module load followed by same-user root transitionThreat-intel articles (5)
crit Inside the Modern SOC: The Identity Front Door · 2026-08-07
high The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software · 2026-08-04
crit Russian Global Webmail Espionage · 2026-07-23
Tracked indicators
Domains (9)
analyticemailmeter.com emailanalytics.com.ua istc-cloud.com mailnalysis.com synacorzimbra.nl zimbra-metadata.com zimbrasoft.com.ua zimbrastat.com zmailanalytics.comIP addresses (9)
104.248.134.194 185.86.79.95 193.238.152.66 194.156.103.193 216.252.238.104 216.252.238.18 216.252.238.64 37.120.247.228 64.226.124.190CVEs (1)
CVE-2025-66376