DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowFall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
Blog

Scattered Spider’s Evolving Tactics: What the 2025 Warning Means for Organizations

By TheFinanceBase Team9 min read

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Scattered Spider’s core approach remains identity-led: impersonate employees, manipulate help desks, take over accounts and use legitimate tools to reach valuable data. A joint warning published on July 29, 2025, by the FBI, CISA, the UK’s National Cyber Security Centre and cyber agencies in Australia and Canada documented more targeted social engineering, additional remote-access and tunneling tools, the Java-based RattyRAT remote-access trojan, and DragonForce ransomware activity. The warning reflects FBI observations through June 2025; it is a valuable threat snapshot, not proof that every tactic remains unchanged or that every later incident attributed to the group is confirmed.

What the warning says changed

The agencies described a financially motivated cybercriminal ecosystem that targets large organizations, including through their IT help desks. Its familiar methods—credential theft, social engineering, MFA manipulation, remote access, data theft and extortion—remain central. The change is an increasingly tailored and flexible version of that playbook, not a wholly new one. The joint advisory and CISA’s technical material describe the observed methods and mitigations.

Persistent pattern Newly documented or emphasized behavior
Phishing, smishing and calls impersonating IT or support staff More targeted spear-phishing and vishing, victim-specific domains, and use of business websites to research targets and make fraudulent contact more credible
Credential theft and MFA manipulation Impersonating actual employees and persuading support staff to disclose credentials, perform remote-support actions, or move MFA enrollment to an attacker-controlled device
Abuse of legitimate administration software A broader toolset that includes additional tunneling and remote-access utilities
Data theft and extortion, sometimes alongside ransomware More documented exfiltration destinations, access to large cloud data stores, and DragonForce ransomware activity, including attention to VMware ESXi
Stealthy access and reconnaissance RattyRAT, a Java-based remote-access trojan, was included in the advisory’s documented toolset

“Newly documented” does not necessarily mean newly created or exclusive to Scattered Spider. Nor does the presence of a named tool establish that the group is involved in a particular incident.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who is Scattered Spider?

Scattered Spider is a label used for a loosely organized cybercriminal ecosystem, not necessarily one conventional gang with a fixed membership and hierarchy. Government and security researchers use overlapping names, including UNC3944, Oktapus or 0ktapus, Octo Tempest, Storm-0875, Muddled Libra and Scatter Swine. Naming conventions and attribution can differ among agencies, vendors and media reports, so an incident linked to one label should not automatically be treated as definitively conducted by the same people as every incident linked to another.

The July 2025 advisory describes financially motivated activity. Microsoft, using the name Octo Tempest, reported activity across multiple industries and described movement from retail, food services, hospitality and insurance activity between April and July 2025 to airline targeting in July. Microsoft said the group can concentrate on one industry for weeks or months before shifting. That pattern matters beyond the named sectors: shared vendors, outsourced help desks and reusable impersonation scripts can spread risk across industries. See Microsoft’s account and protection guidance.

Why the help desk is a high-value target

A help-desk representative may be able to reset passwords, unlock accounts, replace authentication factors, change recovery phone numbers, authorize remote support, or grant access to employees and contractors. These are legitimate support functions. They also create a route around strong technical controls if an attacker can persuade staff that they are speaking to the right person.

That makes help-desk security an identity-verification and authorization problem as much as a technology problem. A technically protected account can still be exposed if a representative changes its recovery path after a convincing call or message. The FBI has separately discussed how deception of help desks can provide system access; see its Ahead of the Threat episode with Charles Carmakal.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Support teams should never treat urgency, a familiar name, caller ID, or knowledge of internal terminology as proof of identity. Verification should rely on a pre-established, independently sourced contact method—not information a caller supplies or facts easily found online. High-impact actions deserve additional approval and a durable audit trail.

MFA still matters, but not all MFA resists phishing

Multifactor authentication remains an essential defense, but “MFA is enabled” is not enough to establish that an account is safe. Attackers may seek one-time codes through impersonation, prompt repeated push approvals, exploit SIM swaps, steal browser session data, use adversary-in-the-middle phishing pages, or convince a help desk to reset MFA or enroll a new device. These are distinct methods; saying an attacker “bypassed MFA” without identifying how can obscure the process that needs fixing.

Phishing-resistant MFA—such as FIDO2/WebAuthn security keys or passkeys—offers stronger protection than SMS codes or push approvals because authentication is cryptographically tied to the legitimate site. Time-based one-time passwords reduce some risks but can still be phished. Stronger MFA is especially important for administrators, help-desk staff and remote access, but it is not immunity: account recovery, session theft, compromised devices and privileged administration still require controls.

Plan recovery as carefully as enrollment. A strong authentication method can be undermined if a caller can persuade support staff to replace it with a weaker one. Include contractors and legacy applications in deployment planning, and make replacement and emergency-access procedures auditable.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How an intrusion may unfold

The following sequence synthesizes the advisory and Microsoft’s reporting. It is a useful model for investigation and defense, not a claim that every incident follows every step.

  1. Reconnaissance: Identify employees, vendors, help-desk procedures, technology brands and internal terminology.
  2. Targeted contact: Use calls, SMS or email with a plausible pretext, sometimes impersonating a real employee or support worker.
  3. Identity compromise: Obtain credentials, a code or session data, or persuade support staff to reset an account or transfer MFA enrollment.
  4. Persistence: Establish another access path, enroll an authenticator, or deploy remote-access software.
  5. Discovery: Explore collaboration tools and business applications; identify privileged users, cloud data, backups and virtualization systems.
  6. Lateral movement: Use valid privileges and familiar administration or tunneling tools to move through the environment.
  7. Data theft: Extract information for leverage, including from cloud services or data platforms.
  8. Extortion or disruption: Threaten publication, deploy ransomware, or do both. The advisory describes data theft and extortion that did not necessarily involve ransomware.
  9. Watch the response: If access to collaboration systems persists, attackers may observe internal incident discussions and adapt to defensive actions.

The advisory describes use of destinations including MEGA and Amazon S3, as well as TOR, Tox, email and encrypted applications for communications. It also discusses targeting access to Snowflake to reach large volumes of data more quickly. That does not establish a Snowflake product vulnerability. Investigators should look at the access path and activity, rather than infer a breach from the platform’s name alone.

Legitimate tools can become an attacker’s access channel

The advisory and Microsoft identify tools such as ScreenConnect, TeamViewer, AnyDesk, Teleport.sh, ngrok, Chisel and AADInternals in the broader activity. Their roles vary by intrusion. These are legitimate or commercially available tools; their presence alone is not evidence of compromise.

This is the practical meaning of “living off the land”: attackers use software that may already be trusted, making a binary malware-only defense inadequate. A known remote-support tool may be needed for operations, yet an unauthorized session through that same tool can create a serious access path. Broadly banning all remote tools may disrupt legitimate work; broadly allowing them can leave attackers a convenient route.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For each remote session, ask: Who initiated it? Was there a valid ticket or change approval? Was the device managed and the operator authorized? Was access limited in time and scope? Was the session recorded where appropriate? Did it occur soon after an MFA reset, from an unusual location, or alongside data transfers? Restrict tools by approved version, administrator group, device posture and network egress; use time-limited, ticket-linked sessions and remove temporary access when work ends.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Priorities for defenders

1. Harden identity recovery and support workflows

  • Enforce phishing-resistant MFA where possible, prioritizing privileged users, help-desk staff and remote access.
  • Require callback or other out-of-band verification through a pre-established contact method before changing passwords, phone numbers, recovery factors or authenticators.
  • Use two-person approval for privileged-account resets, MFA re-enrollment, phone-number or SIM changes, emergency access and remote-support authorization.
  • Use a separate, stronger procedure for privileged identities. Do not base verification solely on personal facts that could be discovered publicly.
  • Log every change to authentication factors and privileged roles; alert on a reset or enrollment followed quickly by a new device, unusual location or privileged activity.
  • Train and test support teams on process adherence, including executive impersonation and hostile or urgent callers—not only email phishing.

2. Control remote administration

  • Maintain an inventory of approved remote-access and tunneling tools, owners, versions and business purposes.
  • Use application controls to restrict unapproved software, while reviewing approved tools for unusual installation, account or session behavior.
  • Limit remote administration to managed devices and approved networks; restrict or closely monitor Remote Desktop Protocol (RDP).
  • Link administrative sessions to tickets, approvals, time limits and session logging where appropriate.
  • Review tools named in the advisory—including AnyDesk, TeamViewer, ScreenConnect, ngrok and Chisel—for context and behavior rather than treating every installation as malicious.

3. Watch identity, cloud data and infrastructure together

Correlate identity events with endpoint, remote-access, cloud-data and virtualization activity. Useful signals include MFA enrollment or reset followed by privileged actions; new identities or unusual service accounts; unexpected domain-trust changes; new remote tools; large or unusual Snowflake queries; transfers to MEGA, unfamiliar Amazon infrastructure or anonymizing services; unusual access to VMware ESXi hosts; and sign-ins from unfamiliar devices, geographies or network providers. Any one alert may have a benign explanation; the sequence and authorization context are what make it actionable.

Monitor collaboration systems during an incident as well. If an attacker might still have access, use a clean, separate channel for sensitive response coordination. Microsoft’s Octo Tempest guidance covers identity, hybrid infrastructure, remote access and detection considerations.

4. Prepare to recover—and to respond to theft without encryption

  • Keep offline backups separate from source systems and test restoration regularly.
  • Protect backup administration with strong, phishing-resistant authentication and segment backup infrastructure from production.
  • Maintain emergency contacts and procedures outside identity, VPN and collaboration systems that could be compromised.
  • Prepare offline instructions for identity-provider, VPN and endpoint containment.
  • Assume data may have been stolen even if ransomware is stopped. Prepare legal, regulatory, law-enforcement and communications decision-making in advance.

Backups limit the effect of encryption and operational disruption; they do not undo data theft or extortion. Recovery plans need both clean restoration and a process for handling stolen information.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What security products can—and cannot—do

Different product categories address different stages of the attack. Phishing-resistant authentication and identity tools reduce account-takeover risk. Help-desk workflow systems can enforce verification and approval steps. EDR/XDR can expose suspicious processes, malware and remote-tool behavior; SIEM and identity-threat detection can correlate account changes with later activity. Privileged-access management and identity-aware remote access can narrow the reach of stolen credentials. Backup and recovery products help restore operations after ransomware.

Those capabilities are useful only when configured, monitored and supported by a response process. Endpoint detection can miss an intrusion that initially consists of valid credentials and a fraudulent reset. Zero-trust or SASE platforms can reduce broad network access, but cannot by themselves stop a support employee from approving a false MFA change. Allowlisting can constrain software, but attackers may abuse a tool already approved. Backup software does not prevent exfiltration. No single product replaces verified support procedures.

What the warning does not establish

The July 29, 2025 advisory is a documented snapshot based principally on FBI observations through June 2025. It does not prove that every described technique remains active or unchanged in 2026, nor does it establish that every reported attack on a retailer, airline or other company was conducted by Scattered Spider. Public reporting and vendor analyses may describe links with differing levels of certainty. Treat attribution as a qualified assessment, not a substitute for investigating evidence from a specific incident.

For defenders, the enduring lesson is broader than any one group or malware family: a support workflow that can change an employee’s authentication path is part of the security perimeter. The most useful test is whether an attacker could persuade one support employee to change a privileged user’s access—and how quickly the organization would detect, validate and reverse that change.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.