THREAT-WATCH logo

THREAT‑WATCH

Threat Actors

Scattered Spider

UNC3944, Octo Tempest, Muddled Libra

ActiveFinancially motivated / extortion

A financially motivated group known for sophisticated social engineering, particularly help-desk impersonation and SIM swapping, that has evolved into deploying ransomware directly.

Unlike most ransomware operators, Scattered Spider's core skill is manipulating people, not exploiting software: calling IT help desks impersonating employees to reset credentials and bypass MFA, or SIM-swapping a target's phone number to intercept authentication codes. A joint FBI/CISA advisory (updated July 2025) documented the group's shift toward deploying DragonForce ransomware and targeting VMware ESXi environments directly. Despite multiple arrests of alleged members through 2024 and 2025, its decentralized structure has kept it operationally resilient, with activity continuing into 2026.

Target Sectors

Technology, telecommunications, financial services, and increasingly critical infrastructure and retail.

Phishing Training