Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

How RaaS Partnerships Expand Scattered Spider’s Attack Capabilities

NCC Group’s August 2025 analysis says Scattered Spider’s reported RaaS relationships can combine social engineering and identity compromise with partners’ ransomware and extortion capabilities. The practical response starts with stronger account recovery, help-desk controls and tested recovery plans.
From TheFinanceBase Team8 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Scattered Spider’s reported relationships with ransomware-as-a-service (RaaS) groups can make its attacks more disruptive by combining social engineering and identity compromise with partners’ ransomware, infrastructure and extortion capabilities. NCC Group’s August 2025 analysis describes a force multiplier, not a single permanent alliance. The distinction matters: organizations need to defend the account and access pathway as well as the ransomware payload.

What NCC Group’s assessment says

NCC Group analysts assessed that Scattered Spider has worked with several RaaS operations, including ALPHV/BlackCat, RansomHub, DragonForce and Qilin. Computer Weekly reported the assessment on September 17, 2025. The public evidence does not establish that all four were partners at the same time, that every Scattered Spider incident involved ransomware, or that the groups formed a permanent organization. Computer Weekly’s account of NCC Group’s analysis

The central implication is specialization: Scattered Spider can focus on the social engineering and identity attacks associated with its operations, while a partner may contribute ransomware tooling, infrastructure or extortion services. That can expand what an intrusion accomplishes without requiring one group to build every capability itself.

What Scattered Spider and RaaS mean

Scattered Spider is a threat-actor label, not a fixed company

Scattered Spider is commonly described as a financially motivated, English-speaking criminal collective or ecosystem. Its historical association is with targeted social engineering, credential theft and identity compromise, rather than one distinctive ransomware brand. Public reporting has linked the name with labels such as Octo Tempest, Muddled Libra, UNC3944 and 0ktapus, but vendor tracking names do not always map neatly to the same people or activity. Microsoft identifies Octo Tempest as also known by those names while noting that its methods and infrastructure evolve. Microsoft’s July 2025 analysis

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

These terms describe different roles, not interchangeable job titles:

  • Threat actor: a person or group associated with malicious activity; the label may cover related operators without proving a single command structure.
  • Affiliate: a participant using or working with a service or criminal operation, often under its own access or operational arrangements.
  • RaaS operator: a criminal service provider that may supply ransomware, infrastructure or negotiation and extortion capabilities to affiliates in return for a share of proceeds.
  • Initial-access specialist or broker: a person or group that obtains access to a victim’s systems; access may be used by the same operator, shared, sold or passed to another party.

In a decentralized ecosystem, one label can cover overlapping participants and relationships. It is more accurate to describe specific links as reported or assessed collaboration than to present Scattered Spider as a conventional, centrally managed gang.

How RaaS divides the work

RaaS is a criminal business model: an operator offers ransomware-related capabilities to affiliates, commonly in exchange for a share of any proceeds. The split varies by arrangement; it should not be treated as one standard rate or one fixed division of responsibilities.

Function Possible responsibility
Target research and employee impersonation Scattered Spider or another initial-access specialist
Credential theft and MFA bypass Scattered Spider operators or another access specialist
Network intrusion and privilege escalation Shared, delegated or carried out by one participant
Data theft Affiliate, partner or both
Encryption payload RaaS operator, affiliate or other tooling
Leak site and extortion negotiation RaaS operator, affiliate or both
Victim selection and access resale Varies by operation
Payment splitting Set by the arrangement; terms vary

This is a model of possible division of labour, not a verified account of every Scattered Spider incident. Public reporting does not establish who performed each stage in each operation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why team-ups can make attacks more effective

Specialization lowers the burden on each participant

An operator skilled at impersonating employees, stealing credentials or manipulating a help desk need not also develop encryption software, maintain extortion infrastructure and run victim negotiations. A partner can supply some of those downstream capabilities. In turn, RaaS operators can gain access to an affiliate’s intrusion skills or victim access.

Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Ready-made capabilities can speed escalation

Once attackers have valid credentials and privileged access, a prepared ransomware operation can shorten the route to data theft, extortion or encryption. Microsoft reported Octo Tempest activity involving DragonForce ransomware and VMware ESXi environments; a joint FBI/CISA advisory also describes Scattered Spider actors using multiple ransomware variants, including DragonForce. These reports support the possibility of ransomware being part of the operation, not the claim that every intrusion ends in encryption. Microsoft’s report · FBI/CISA joint advisory, July 29, 2025

Multiple relationships offer options

Different RaaS operations may offer different malware, infrastructure, negotiation processes or targeting preferences. NCC-linked reporting says Scattered Spider has been associated with several groups, rather than only one ransomware brand. That may give an affiliate options, although public reporting does not show that every named group was an active partner at the same time.

NCC/Fox-IT reporting described affiliate-friendly terms and reported commissions of at least 80% in some cases. That is an attributed report about particular arrangements, not an independently established universal RaaS rate. Fox-IT’s August 2025 Threat Pulse summary

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Collaboration can complicate attribution

An intrusion may involve one participant obtaining access, another moving through a network and a third supplying ransomware or extortion infrastructure. That can make it harder to attribute the entire incident from a ransom note or malware family alone. Multiple criminal relationships could also reduce reliance on a single brand if one operation is disrupted. That is a plausible resilience effect, not proof of a formal business-continuity plan.

Which ransomware groups have been linked to Scattered Spider?

NCC-linked coverage identifies four groups in connection with Scattered Spider. The list reflects threat-intelligence reporting, not a formal membership roster or a claim that each group was involved in every incident.

Rank #3
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Ransomware group What the reporting supports
ALPHV/BlackCat Identified in NCC-linked reporting as a group associated with Scattered Spider.
RansomHub Identified in NCC-linked reporting as a group associated with Scattered Spider.
DragonForce Identified in NCC-linked reporting; the FBI/CISA advisory and Microsoft also report DragonForce use in activity associated with the actor.
Qilin Identified in NCC-linked reporting. NCC’s August dataset recorded 53 observed Qilin attacks, 16% of that dataset’s reported total.

The Qilin figures describe NCC’s tracked incidents, not all ransomware attacks worldwide. NCC Group’s August 2025 public summary

How an identity attack can become an extortion incident

Government reporting describes techniques that help explain the connection between social engineering and ransomware consequences. The following is a defensive outline of a possible path, not a claim that every incident follows these steps:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. An attacker impersonates an employee or contractor, or otherwise targets an account holder.
  2. The attacker seeks credentials or persuades a help desk to reset a password, MFA factor or device enrollment.
  3. With access, the attacker may reach cloud or on-premises resources and use legitimate remote-access or administrative tools.
  4. From a privileged position, attackers may move laterally, access sensitive information and prepare data for removal.
  5. Data may be exfiltrated for extortion; ransomware may also be deployed, including against virtualization environments.
  6. The victim may face a demand involving stolen data, encryption, or both.

The July 29, 2025 joint FBI/CISA advisory—based on investigations and reporting available through June 2025—lists phishing, MFA push-bombing or fatigue, SIM swapping, help-desk social engineering, credential theft, remote-access tools, abuse of legitimate administrative utilities, ransomware and data theft for extortion. CISA’s advisory announcement

Microsoft’s July 16, 2025 reporting adds that recent Octo Tempest activity crossed both on-premises and cloud environments and included VMware ESXi attacks. For defenders, an identity incident can therefore become an enterprise-wide problem spanning accounts, endpoints, cloud services and virtualization hosts. Microsoft’s Octo Tempest coverage

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What NCC’s August 2025 figures do—and do not—show

NCC Group reported 328 observed ransomware attacks in August 2025, a 13% month-on-month decline and the fifth consecutive month below 500 in its tracked dataset. Its summary identified industrials as the most targeted sector, at 37%. Computer Weekly reported that North America accounted for 57% and Europe, including the UK, 24%—81% combined—of the attacks in the account of NCC’s data. These are observed figures from NCC’s collection, not a complete global census; totals can differ with collection methods and reporting visibility. Computer Weekly’s account · NCC Group’s August summary

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

A lower observed count does not establish that the remaining incidents were less severe. Frequency, victim impact, data theft, disruption and attribution confidence are different measures. Criminal specialization can make an individual intrusion more damaging even while a monitored monthly total falls.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What organizations should change

Make identity recovery as strong as sign-in

The joint advisory recommends phishing-resistant MFA. FIDO2/WebAuthn security keys or equivalent passkey-based controls can reduce exposure to phishing and push-fatigue attacks, but MFA alone does not stop help-desk manipulation, compromised endpoints, session-token theft or abuse of an already authenticated session. FBI/CISA recommendations

  • Require phishing-resistant MFA for privileged users and, where practical, across the organization.
  • Use high-assurance identity checks before password resets, MFA resets or new device enrollment.
  • Use a known, pre-existing callback channel or independent approval for sensitive changes; do not rely on caller ID or easily researched personal facts.
  • Separate privileged-account recovery procedures from routine help-desk workflows.
  • Log and alert on repeated verification failures, new authenticators, risky sign-ins, token issuance and unusual MFA changes.
  • Revoke sessions, tokens and newly registered authenticators promptly when compromise is suspected.

Treat help-desk and identity administrators as privileged roles

Support staff can reset access factors that protect the rest of the organization. Limit reset and enrollment permissions by role, review contractor and outsourced support arrangements, record sensitive actions and test procedures through authorized social-engineering exercises. A process that depends on a caller sounding convincing is not a reliable identity control.

Constrain remote-management tools

The advisory recommends application controls and controlled use of remote-access software. Maintain an approved software inventory, restrict unapproved remote-management tools and alert when tools such as AnyDesk or other RMM utilities appear unexpectedly. Where operationally practical, use application allowlisting; preserve logs of administrative sessions and command execution, and investigate legitimate tools launched from unusual paths or accounts.

Plan for stolen data and virtualization recovery

  • Keep offline or isolated backups separate from production systems and test restores regularly, as the joint advisory recommends.
  • Protect virtualization hosts and management planes, including VMware ESXi, with separate administrative controls and monitoring.
  • Monitor for unusual bulk data access, staging and outbound transfer—not only encryption activity.
  • Prepare an incident plan for extortion without encryption as well as for systems being encrypted.
  • Agree in advance on legal, regulatory, communications and law-enforcement escalation paths.

Recovery plans should include identity infrastructure and hypervisors, not just user files. Backups reachable through the same compromised credentials as production systems may not provide dependable recovery.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What is known, assessed and unresolved

Statement How to interpret it
Scattered Spider actors use social engineering and identity attacks. Strongly supported by the FBI/CISA advisory and Microsoft reporting.
Actors associated with the group have used DragonForce. Supported by the advisory and Microsoft reporting; this does not mean every operation used it.
Scattered Spider has worked with particular RaaS brands. An NCC Group threat-intelligence assessment reported by Computer Weekly; treat the relationships as assessed, not as a formal roster.
All aliases refer to exactly the same people. Not established. Vendor labels can overlap without being perfectly interchangeable.
The partnerships are permanent, centrally managed or governed by one command structure. Not established by the cited public reporting.

The evidence supports an operational lesson more clearly than an organizational chart: named ransomware brands are only one part of the threat. Defenders should investigate the access path—help-desk interactions, credential and MFA changes, remote tools, privilege use, data movement and encryption—rather than treating a ransom note as a complete account of who did what.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.