Ransomware, Threat Intelligence, Security Staff Acquisition & Development
‘One of the most dangerous financial criminal groups’ responsible for MGM cyberattack

Scattered Spider, aka Octo Tempest, 0ktapus and UNC3944, responsible for September's $100 million attack on MGM Resorts. (Adobe Stock)
Scattered Spider, the threat gang responsible for recent attacks against MGM International and Caesars Entertainment, amongst others, has been described by Microsoft as “one of the most dangerous financial criminal groups."In an Oct. 25 post, Microsoft’s threat intelligence team detailed what it describes as Scattered Spider’s “extensive range” of tactics, techniques, and procedures (TTPs), saying the gang “crosses boundaries to facilitate extortion, encryption, and destruction.”Scattered Spider’s destructive capabilities were on full display in Las Vegas in September when it crippled multiple IT systems across several MGM properties in a sprawling attack that exposed customer data and cost the company around $100 million. Tracked by Microsoft as Octo Tempest, and also known as 0ktapus and UNC3944, the gang began deploying ALPHV/BlackCat ransomware in the middle of this year and has focused its attacks on VMware ESXi servers.As well as having an extensive arsenal of TTPs that enable it to successfully attack complex hybrid environments, Scattered Spider’s prowess is further enhanced by its ability to carry out what Microsoft calls “social engineering with a twist.”“The threat actor performs research on the organization and identifies targets to effectively impersonate victims, mimicking idiolect on phone calls and understanding personal identifiable information to trick technical administrators into performing password resets and resetting multifactor authentication (MFA) methods,” the threat intelligence team said.“These actors use personal information, such as home addresses and family names, along with physical threats to coerce victims into sharing credentials for corporate access.”
An In-Depth Guide to Ransomware
Get essential knowledge and practical strategies to protect your organization from ransomware attacks.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds