2026-08-10NOTABLEESXi's minimal shell is expressive enough to hide commands, and its logging captures the parsing stage rather than the result
Scattered Spider
actor · actor:scattered-spider single-source
Decentralised, English-fluent cybercrime collective (not a single hierarchical group) responsible for over 100 network intrusions since 2022 using vishing/smishing SSO-lookalike phishing, SIM-swap and help-desk-impersonation initial access, and BlackCat/ALPHV or DragonForce ransomware deployment. Group-IB (2026-07-07) reframes it as a movement of independent 3-5-person subclusters unified by shared TTPs, casting its own '0ktapus' designation and Microsoft's Octo Tempest, Mandiant's UNC3944 and Palo Alto's Muddled Libra as overlapping subcluster labels rather than distinct groups.
Aliases: 0ktapus, Octo Tempest, UNC3944, Muddled Libra
Coverage
4
2 about it · 2 mentions · first 2026-05-19 → last 2026-08-10
Latest activity
2026-08-10
ESXi's minimal shell is expressive enough to hide commands, and its logging captures the parsing stage rather…
Peak priority
notable
2 notable
Targets
public-sector
sectors: public-sector, healthcare, energy · regions: europe, uk
Sources cited
13
10 hosts
2026-05-194 appearances2026-08-10
Defender insights
What each entry about Scattered Spider tells a defender to do, newest first.
Triage
Latest update
Story timeline
Every entry that names Scattered Spider, newest first. Rows tagged mention only name it in passing: they are listed for completeness and add nothing to the action items, pivots or ATT&CK profile on this page.
- 2026-08-10CrowdStrike catalogues 21 working command-obfuscation techniques inside VMware ESXi's BusyBox ash shell, and shell logs record the command before expansion, so the logged string is not what ran
- 2026-07-10'Helix' data-extortion cluster pairs manager-impersonation vishing with device-code phishing and automated SharePoint exfiltration
- 2026-06-23Two Scattered Spider members plead guilty over the 2024 Transport for London intrusion
- 2026-05-19Grafana Labs CoinbaseCartel breach; victim confirms source-code-only theft, no customer data, ransom rejected
Hunting pivots
Affected products
ATT&CK techniques (9 across 7 tactics)
9 techniques observed across 2 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- ReconnaissanceGather Victim Identity Information: Credentials
- Initial AccessValid Accounts · Phishing · Phishing: Spearphishing Voice
- ExecutionCommand and Scripting Interpreter: Unix Shell
- PersistenceValid Accounts · Account Manipulation
- Privilege EscalationValid Accounts · Account Manipulation
- StealthObfuscated Files or Information · Valid Accounts · Deobfuscate/Decode Files or Information
- Credential AccessMulti-Factor Authentication Request Generation
Reconnaissance TA0043
T1589.001Gather Victim Identity Information: Credentials×1
Adversaries may gather credentials that can be used during targeting. Account credentials gathered by adversaries may be those directly associated with the target victim organization or attempt to take advantage of the tendency for users to use the same passwords across personal and business accounts.
Evidence: 2026-06-23/two-scattered-spider-members-plead-guilty-over-the-2024-tran · ATT&CK page ↗
Initial Access TA0001
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-06-23/two-scattered-spider-members-plead-guilty-over-the-2024-tran · ATT&CK page ↗
T1566Phishing×1
Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.
Evidence: 2026-06-23/two-scattered-spider-members-plead-guilty-over-the-2024-tran · ATT&CK page ↗
T1566.004Phishing: Spearphishing Voice×1
Adversaries may use voice communications to ultimately gain access to victim systems. Spearphishing voice is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of manipulating a user into providing access to systems through a phone call or other forms of voice communications. Spearphishing frequently involves social engineering techniques, such as posing as a trusted source (ex: Impersonation) and/or creating a sense of urgency or alarm for the recipient.
Evidence: 2026-06-23/two-scattered-spider-members-plead-guilty-over-the-2024-tran · ATT&CK page ↗
Execution TA0002
T1059.004Command and Scripting Interpreter: Unix Shell×1
Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the primary command prompt on Linux, macOS, and ESXi systems, though many variations of the Unix shell exist (e.g. sh, ash, bash, zsh, etc.) depending on the specific OS or distribution. Unix shells can control every aspect of a system, with certain commands requiring elevated privileges.
Evidence: 2026-08-10/esxi-busybox-ash-command-obfuscation-21-techniques · ATT&CK page ↗
Persistence TA0003
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-06-23/two-scattered-spider-members-plead-guilty-over-the-2024-tran · ATT&CK page ↗
T1098Account Manipulation×1
Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials.
Evidence: 2026-06-23/two-scattered-spider-members-plead-guilty-over-the-2024-tran · ATT&CK page ↗
Privilege Escalation TA0004
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-06-23/two-scattered-spider-members-plead-guilty-over-the-2024-tran · ATT&CK page ↗
T1098Account Manipulation×1
Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials.
Evidence: 2026-06-23/two-scattered-spider-members-plead-guilty-over-the-2024-tran · ATT&CK page ↗
Stealth TA0005
T1027Obfuscated Files or Information×1
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.
Evidence: 2026-08-10/esxi-busybox-ash-command-obfuscation-21-techniques · ATT&CK page ↗
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-06-23/two-scattered-spider-members-plead-guilty-over-the-2024-tran · ATT&CK page ↗
T1140Deobfuscate/Decode Files or Information×1
Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system.
Evidence: 2026-08-10/esxi-busybox-ash-command-obfuscation-21-techniques · ATT&CK page ↗
Credential Access TA0006
T1621Multi-Factor Authentication Request Generation×1
Adversaries may attempt to bypass multi-factor authentication (MFA) mechanisms and gain access to accounts by generating MFA requests sent to users.
Evidence: 2026-06-23/two-scattered-spider-members-plead-guilty-over-the-2024-tran · ATT&CK page ↗
Entries about Scattered Spider (2)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- ShinyHunters×2
- Akira×1
- Grafana Labs CoinbaseCartel breach×1
- Helix×1
- Living Off the Pipeline×1
- Microsoft 365×1
- Microsoft Entra ID×1
- Microsoft SharePoint×1
Where this entity is cited
Source distribution
- bleepingcomputer.com2 (15%)
- nationalcrimeagency.gov.uk2 (15%)
- theregister.com2 (15%)
- ca.news.yahoo.com1 (8%)
- cps.gov.uk1 (8%)
- crowdstrike.com1 (8%)
- itv.com1 (8%)
- reliaquest.com1 (8%)
- other2 (15%)
All cited sources (13)
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/grafana-says-stolen-github-token-let-hackers-steal-codebase/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/new-helix-vishing-group-emerges-in-sharepoint-data-theft-attacks/
- ca.news.yahoo.comYahoo/BBChttps://ca.news.yahoo.com/two-men-plead-guilty-over-143055796.html
- cps.gov.ukUK Crown Prosecution Service (CPS)https://www.cps.gov.uk/national-news/news/cyberhackers-who-targeted-tfl-jailed-more-five-years-each
- crowdstrike.comCrowdStrikehttps://www.crowdstrike.com/en-us/blog/crowdstrike-hunts-for-shell-command-obfuscation-vmware-esx/
- itv.comITV Newshttps://www.itv.com/news/london/2026-06-22/two-young-men-admit-carrying-out-cyber-attack-on-transport-for-london
- nationalcrimeagency.gov.ukUK National Crime Agencyhttps://www.nationalcrimeagency.gov.uk/news/cyber-criminals-who-hacked-into-transport-for-londons-computer-network-are-convicted
- nationalcrimeagency.gov.ukUK National Crime Agency (NCA)https://www.nationalcrimeagency.gov.uk/news/two-sentenced-for-hacking-transport-for-london-in-uk-s-biggest-ever-cyber-crime-case
- reliaquest.comReliaQuesthttps://reliaquest.com/blog/threat-spotlight-helix-new-name-in-data-extortion-ecosystem
- securityweek.comSecurityWeekhttps://www.securityweek.com/grafana-confirms-breach-after-hackers-claim-they-stole-data/
- thehackernews.comThe Hacker Newshttps://thehackernews.com/2026/05/grafana-github-token-breach-led-to.html
- theregister.comThe Registerhttps://www.theregister.com/cyber-crime/2026/05/18/grafana-labs-admits-attackers-downloaded-its-codebase-from-github/5241686
- theregister.comThe Registerhttps://www.theregister.com/cyber-crime/2026/07/16/brit-scattered-spider-duo-handed-tickets-to-prison-over-transport-for-london-attack/5272446