85
Sophistication
2022
First Seen
90
Notoriety
77
Stealth
86
Immersive Rating
90
Impact
48
Tactics Variety

Scattered Spider

English-speaking group thought to be comprised of British and American nationals. Known for high-profile breaches via social engineering. Compromised MGM Resorts in 2023, causing major outages. Uses SIM swapping and MFA fatigue to bypass security.

Key behaviours to watch:

  • Targeted spear-phishing leading to domain compromise and lateral movement.
  • Bulk exfiltration of archives via RAR compression and custom utilities (GETMAIL, MAPIGET).
  • Long dwell-time persistence with scheduled tasks, reused credentials, and stealthy C2.

Immersive coverage includes:

  • Threat Actors and Threats > APT Campaigns
  • Threat Hunting > APT29 / FIN7 analogues
  • Incident Response > Containment & Eradication
Indian Cyber Force
80
2013
73
72
72
85
75
Kamacite
88
2013
86
83
85
81
86
Kimusky
62
2021
88
43
86
78
66
Lapsus$
89
2009
92
73
85
81
87
Lazarus Group
95
2008
85
92
93
94
88
LulzSec
50
2011
75
38
62
72
52
MAGNALLIUM
80
2013
56
73
79
58
74
Onyx Sleet
85
2014
80
80
84
71
77