MITRE ATT&CK G1015

Scattered Spider / UNC5537

View MITRE Group Page ↗
Aliases: UNC3944, Octo Tempest, Muddled Libra, Starfrost
Official Attribution Source: CISA & FBI Joint Advisory AA23-320A and Mandiant UNC5537 Report

Key Facts

Jurisdiction
Transnational (US / UK / Canada)
Geographic origin
Cases
2
Prosecution matters
Defendants
0
Indicted individuals
Sanctions
0
OFAC designations
  • Attributed Country: Transnational (US / UK / Canada).
  • ATT&CK Group Reference: G1015 (Scattered Spider / UNC5537).
  • Linked to 2 primary court prosecution records.
  • Identified 0 individually charged operatives.

Primary ATT&CK Techniques Employed

ATT&CK Techniques Mapped to Scattered Spider / UNC5537 Technique frequencies extracted from verified indictments for Scattered Spider / UNC5537. T1078 Valid Accounts 1 incidents T1110 Brute Force 1 incidents T1567 Exfiltration Over Web Service 1 incidents
Technique frequencies extracted from verified indictments for Scattered Spider / UNC5537.
ATT&CK Techniques Mapped to Scattered Spider / UNC5537
Technique Frequency
T1078 Valid Accounts 1 incidents
T1110 Brute Force 1 incidents
T1567 Exfiltration Over Web Service 1 incidents

Prosecution Cases Attributed to This Actor

alleged 2024-05-23

Snowflake Enterprise Credential Stuffing & Customer Cloud Thefts

Financially motivated threat actor collective UNC5537 systematically infiltrated over 165 corporate customer tenants hosted on Snowflake (including Ticketmaster, Santander Bank, Advance Auto Parts, and LendingTree). Attackers leveraged infostealer malware logs dating back years against enterprise user accounts that lacked multi-factor authentication and IP network allowlists, exfiltrating billions of consumer records.

3 techniques View case →
investigation 2024-07-12

AT&T Cloud Telecom Call and Text Metadata Exfiltration

Illegal exfiltration of call and text interaction metadata spanning six months for approximately 110 million AT&T wireless customers. Intrusion stemmed from an illicit access point to a third-party Snowflake cloud environment, leading to a 5.7 Bitcoin extortion fee paid through an intermediary to obtain verified video evidence of dataset deletion.

2 techniques View case →
OPERATIONAL DEFENSE

Targeted Defensive Hardening for Scattered Spider / UNC5537

Run Stack Audit →

Primary Initial Access Defense

Enforce hardware FIDO2 multi-factor authentication across all perimeter VPN, Citrix, and cloud data portals. Prohibit SMS or push-based MFA that can be bypassed via vishing or SIM swapping.

Lateral Movement Interception

Restrict internal SMB (port 445) and RPC traversal between workstation subnets. Implement tiered Active Directory administration so domain administrator credentials are never cached on endpoints.