What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Scattered Spider’s core approach remains identity-led: impersonate employees, manipulate help desks, take over accounts and use legitimate tools to reach valuable data. A joint warning published on July 29, 2025, by the FBI, CISA, the UK’s National Cyber Security Centre and cyber agencies in Australia and Canada documented more targeted social engineering, additional remote-access and tunneling tools, the Java-based RattyRAT remote-access trojan, and DragonForce ransomware activity. The warning reflects FBI observations through June 2025; it is a valuable threat snapshot, not proof that every tactic remains unchanged or that every later incident attributed to the group is confirmed.
What the warning says changed
The agencies described a financially motivated cybercriminal ecosystem that targets large organizations, including through their IT help desks. Its familiar methods—credential theft, social engineering, MFA manipulation, remote access, data theft and extortion—remain central. The change is an increasingly tailored and flexible version of that playbook, not a wholly new one. The joint advisory and CISA’s technical material describe the observed methods and mitigations.
| Persistent pattern | Newly documented or emphasized behavior |
|---|---|
| Phishing, smishing and calls impersonating IT or support staff | More targeted spear-phishing and vishing, victim-specific domains, and use of business websites to research targets and make fraudulent contact more credible |
| Credential theft and MFA manipulation | Impersonating actual employees and persuading support staff to disclose credentials, perform remote-support actions, or move MFA enrollment to an attacker-controlled device |
| Abuse of legitimate administration software | A broader toolset that includes additional tunneling and remote-access utilities |
| Data theft and extortion, sometimes alongside ransomware | More documented exfiltration destinations, access to large cloud data stores, and DragonForce ransomware activity, including attention to VMware ESXi |
| Stealthy access and reconnaissance | RattyRAT, a Java-based remote-access trojan, was included in the advisory’s documented toolset |
“Newly documented” does not necessarily mean newly created or exclusive to Scattered Spider. Nor does the presence of a named tool establish that the group is involved in a particular incident.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallWho is Scattered Spider?
Scattered Spider is a label used for a loosely organized cybercriminal ecosystem, not necessarily one conventional gang with a fixed membership and hierarchy. Government and security researchers use overlapping names, including UNC3944, Oktapus or 0ktapus, Octo Tempest, Storm-0875, Muddled Libra and Scatter Swine. Naming conventions and attribution can differ among agencies, vendors and media reports, so an incident linked to one label should not automatically be treated as definitively conducted by the same people as every incident linked to another.
#1 Best Overall
The July 2025 advisory describes financially motivated activity. Microsoft, using the name Octo Tempest, reported activity across multiple industries and described movement from retail, food services, hospitality and insurance activity between April and July 2025 to airline targeting in July. Microsoft said the group can concentrate on one industry for weeks or months before shifting. That pattern matters beyond the named sectors: shared vendors, outsourced help desks and reusable impersonation scripts can spread risk across industries. See Microsoft’s account and protection guidance.
Why the help desk is a high-value target
A help-desk representative may be able to reset passwords, unlock accounts, replace authentication factors, change recovery phone numbers, authorize remote support, or grant access to employees and contractors. These are legitimate support functions. They also create a route around strong technical controls if an attacker can persuade staff that they are speaking to the right person.
That makes help-desk security an identity-verification and authorization problem as much as a technology problem. A technically protected account can still be exposed if a representative changes its recovery path after a convincing call or message. The FBI has separately discussed how deception of help desks can provide system access; see its Ahead of the Threat episode with Charles Carmakal.
Free tools Windows power users keep installed
One-click scans. No signup required.
Support teams should never treat urgency, a familiar name, caller ID, or knowledge of internal terminology as proof of identity. Verification should rely on a pre-established, independently sourced contact method—not information a caller supplies or facts easily found online. High-impact actions deserve additional approval and a durable audit trail.
MFA still matters, but not all MFA resists phishing
Multifactor authentication remains an essential defense, but “MFA is enabled” is not enough to establish that an account is safe. Attackers may seek one-time codes through impersonation, prompt repeated push approvals, exploit SIM swaps, steal browser session data, use adversary-in-the-middle phishing pages, or convince a help desk to reset MFA or enroll a new device. These are distinct methods; saying an attacker “bypassed MFA” without identifying how can obscure the process that needs fixing.
Phishing-resistant MFA—such as FIDO2/WebAuthn security keys or passkeys—offers stronger protection than SMS codes or push approvals because authentication is cryptographically tied to the legitimate site. Time-based one-time passwords reduce some risks but can still be phished. Stronger MFA is especially important for administrators, help-desk staff and remote access, but it is not immunity: account recovery, session theft, compromised devices and privileged administration still require controls.
Plan recovery as carefully as enrollment. A strong authentication method can be undermined if a caller can persuade support staff to replace it with a weaker one. Include contractors and legacy applications in deployment planning, and make replacement and emergency-access procedures auditable.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →How an intrusion may unfold
The following sequence synthesizes the advisory and Microsoft’s reporting. It is a useful model for investigation and defense, not a claim that every incident follows every step.
Rank #3
- Reconnaissance: Identify employees, vendors, help-desk procedures, technology brands and internal terminology.
- Targeted contact: Use calls, SMS or email with a plausible pretext, sometimes impersonating a real employee or support worker.
- Identity compromise: Obtain credentials, a code or session data, or persuade support staff to reset an account or transfer MFA enrollment.
- Persistence: Establish another access path, enroll an authenticator, or deploy remote-access software.
- Discovery: Explore collaboration tools and business applications; identify privileged users, cloud data, backups and virtualization systems.
- Lateral movement: Use valid privileges and familiar administration or tunneling tools to move through the environment.
- Data theft: Extract information for leverage, including from cloud services or data platforms.
- Extortion or disruption: Threaten publication, deploy ransomware, or do both. The advisory describes data theft and extortion that did not necessarily involve ransomware.
- Watch the response: If access to collaboration systems persists, attackers may observe internal incident discussions and adapt to defensive actions.
The advisory describes use of destinations including MEGA and Amazon S3, as well as TOR, Tox, email and encrypted applications for communications. It also discusses targeting access to Snowflake to reach large volumes of data more quickly. That does not establish a Snowflake product vulnerability. Investigators should look at the access path and activity, rather than infer a breach from the platform’s name alone.
Legitimate tools can become an attacker’s access channel
The advisory and Microsoft identify tools such as ScreenConnect, TeamViewer, AnyDesk, Teleport.sh, ngrok, Chisel and AADInternals in the broader activity. Their roles vary by intrusion. These are legitimate or commercially available tools; their presence alone is not evidence of compromise.
This is the practical meaning of “living off the land”: attackers use software that may already be trusted, making a binary malware-only defense inadequate. A known remote-support tool may be needed for operations, yet an unauthorized session through that same tool can create a serious access path. Broadly banning all remote tools may disrupt legitimate work; broadly allowing them can leave attackers a convenient route.
For each remote session, ask: Who initiated it? Was there a valid ticket or change approval? Was the device managed and the operator authorized? Was access limited in time and scope? Was the session recorded where appropriate? Did it occur soon after an MFA reset, from an unusual location, or alongside data transfers? Restrict tools by approved version, administrator group, device posture and network egress; use time-limited, ticket-linked sessions and remove temporary access when work ends.
Rank #4
Priorities for defenders
1. Harden identity recovery and support workflows
- Enforce phishing-resistant MFA where possible, prioritizing privileged users, help-desk staff and remote access.
- Require callback or other out-of-band verification through a pre-established contact method before changing passwords, phone numbers, recovery factors or authenticators.
- Use two-person approval for privileged-account resets, MFA re-enrollment, phone-number or SIM changes, emergency access and remote-support authorization.
- Use a separate, stronger procedure for privileged identities. Do not base verification solely on personal facts that could be discovered publicly.
- Log every change to authentication factors and privileged roles; alert on a reset or enrollment followed quickly by a new device, unusual location or privileged activity.
- Train and test support teams on process adherence, including executive impersonation and hostile or urgent callers—not only email phishing.
2. Control remote administration
- Maintain an inventory of approved remote-access and tunneling tools, owners, versions and business purposes.
- Use application controls to restrict unapproved software, while reviewing approved tools for unusual installation, account or session behavior.
- Limit remote administration to managed devices and approved networks; restrict or closely monitor Remote Desktop Protocol (RDP).
- Link administrative sessions to tickets, approvals, time limits and session logging where appropriate.
- Review tools named in the advisory—including AnyDesk, TeamViewer, ScreenConnect, ngrok and Chisel—for context and behavior rather than treating every installation as malicious.
3. Watch identity, cloud data and infrastructure together
Correlate identity events with endpoint, remote-access, cloud-data and virtualization activity. Useful signals include MFA enrollment or reset followed by privileged actions; new identities or unusual service accounts; unexpected domain-trust changes; new remote tools; large or unusual Snowflake queries; transfers to MEGA, unfamiliar Amazon infrastructure or anonymizing services; unusual access to VMware ESXi hosts; and sign-ins from unfamiliar devices, geographies or network providers. Any one alert may have a benign explanation; the sequence and authorization context are what make it actionable.
Monitor collaboration systems during an incident as well. If an attacker might still have access, use a clean, separate channel for sensitive response coordination. Microsoft’s Octo Tempest guidance covers identity, hybrid infrastructure, remote access and detection considerations.
4. Prepare to recover—and to respond to theft without encryption
- Keep offline backups separate from source systems and test restoration regularly.
- Protect backup administration with strong, phishing-resistant authentication and segment backup infrastructure from production.
- Maintain emergency contacts and procedures outside identity, VPN and collaboration systems that could be compromised.
- Prepare offline instructions for identity-provider, VPN and endpoint containment.
- Assume data may have been stolen even if ransomware is stopped. Prepare legal, regulatory, law-enforcement and communications decision-making in advance.
Backups limit the effect of encryption and operational disruption; they do not undo data theft or extortion. Recovery plans need both clean restoration and a process for handling stolen information.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →What security products can—and cannot—do
Different product categories address different stages of the attack. Phishing-resistant authentication and identity tools reduce account-takeover risk. Help-desk workflow systems can enforce verification and approval steps. EDR/XDR can expose suspicious processes, malware and remote-tool behavior; SIEM and identity-threat detection can correlate account changes with later activity. Privileged-access management and identity-aware remote access can narrow the reach of stolen credentials. Backup and recovery products help restore operations after ransomware.
Best Value
Those capabilities are useful only when configured, monitored and supported by a response process. Endpoint detection can miss an intrusion that initially consists of valid credentials and a fraudulent reset. Zero-trust or SASE platforms can reduce broad network access, but cannot by themselves stop a support employee from approving a false MFA change. Allowlisting can constrain software, but attackers may abuse a tool already approved. Backup software does not prevent exfiltration. No single product replaces verified support procedures.
What the warning does not establish
The July 29, 2025 advisory is a documented snapshot based principally on FBI observations through June 2025. It does not prove that every described technique remains active or unchanged in 2026, nor does it establish that every reported attack on a retailer, airline or other company was conducted by Scattered Spider. Public reporting and vendor analyses may describe links with differing levels of certainty. Treat attribution as a qualified assessment, not a substitute for investigating evidence from a specific incident.
For defenders, the enduring lesson is broader than any one group or malware family: a support workflow that can change an employee’s authentication path is part of the security perimeter. The most useful test is whether an attacker could persuade one support employee to change a privileged user’s access—and how quickly the organization would detect, validate and reverse that change.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

