Scattered Spider has extracted the NTDS.dit file by creating volume shadow copies of virtual domain controller disks.8910
group
Scattered Spider G1015
- Created
- 5 July 2023
- Last modified
- 31 July 2026
- Aliases
- Scattered Spider · Roasted 0ktapus · Octo Tempest · Storm-0875 · UNC3944
Scattered Spider is a native English-speaking cybercriminal group active since at least 2022. [1] [2] The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. [2] Scattered Spider relies heavily on social engineering, including impersonating IT and help-desk staff, to gain initial access, bypass multi-factor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. [3] [4] [5] Scattered Spider had expanded into hybrid cloud and identity environments, using help-desk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365. [6]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference G1015
During C0027, Scattered Spider performed domain replication.11
Scattered Spider has created volume shadow copies of virtual domain controller disks to extract the NTDS.dit file.12
Scattered Spider has used network reconnaissance commands for discovery including ping and nltest.13
Scattered Spider can enumerate remote systems, such as VMware vCenter infrastructure.14
Scattered Spider has used RDP to enable lateral movement.15
Standing G1015
Reach is how much of ATT&CK this group touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 176 ATT&CK groups only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
91st percentile · 91% of 176 ATT&CK groups have this many Enterprise techniques or fewer.
100th percentile · None of the 176 ATT&CK groups has more tactics spanned — the highest in the population.
81st percentile · 81% of 176 ATT&CK groups have this many tools and malware or fewer.
89% of the population shares a single value across only 4 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
38th percentile · 62% of 176 ATT&CK groups have more detection rules per technique.
Detection coverage G1015
1730 distinct rules cover the 64 techniques recorded for this group. The 1924 technique-to-rule mappings resolve to 1730 distinct rules, because one rule can cover several techniques. 1041 Sigma · 689 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org