
THREAT‑WATCH
Threat Actors
Scattered Spider
UNC3944, Octo Tempest, Muddled Libra
A financially motivated group known for sophisticated social engineering, particularly help-desk impersonation and SIM swapping, that has evolved into deploying ransomware directly.
Unlike most ransomware operators, Scattered Spider's core skill is manipulating people, not exploiting software: calling IT help desks impersonating employees to reset credentials and bypass MFA, or SIM-swapping a target's phone number to intercept authentication codes. A joint FBI/CISA advisory (updated July 2025) documented the group's shift toward deploying DragonForce ransomware and targeting VMware ESXi environments directly. Despite multiple arrests of alleged members through 2024 and 2025, its decentralized structure has kept it operationally resilient, with activity continuing into 2026.
Target Sectors
Technology, telecommunications, financial services, and increasingly critical infrastructure and retail.