85
Sophistication
2022
First Seen
90
Notoriety
77
Stealth
86
Immersive Rating
90
Impact
48
Tactics Variety

Scattered Spider

English-speaking group thought to be comprised of British and American nationals. Known for high-profile breaches via social engineering. Compromised MGM Resorts in 2023, causing major outages. Uses SIM swapping and MFA fatigue to bypass security.

Key behaviours to watch:

  • Targeted spear-phishing leading to domain compromise and lateral movement.
  • Bulk exfiltration of archives via RAR compression and custom utilities (GETMAIL, MAPIGET).
  • Long dwell-time persistence with scheduled tasks, reused credentials, and stealthy C2.

Immersive coverage includes:

  • Threat Actors and Threats > APT Campaigns
  • Threat Hunting > APT29 / FIN7 analogues
  • Incident Response > Containment & Eradication
R00TK1T ISC CyberTeam
40
2023
50
41
55
40
42
Salt Typhoon
95
2021
89
98
97
94
83
Sandworm Team
95
2009
86
96
96
97
89
Scattered Spider
85
2022
90
77
86
90
48
Sector 16
57
2025
41
59
51
45
66
SocGhoulish
48
2018
50
53
63
66
68
StrongPity
75
2012
50
55
42
60
70
Transparent Tribe
70
2013
65
68
45
67
64