Scattered Spider / UNC5537
View MITRE Group Page ↗Key Facts
- Attributed Country: Transnational (US / UK / Canada).
- ATT&CK Group Reference: G1015 (Scattered Spider / UNC5537).
- Linked to 2 primary court prosecution records.
- Identified 0 individually charged operatives.
Primary ATT&CK Techniques Employed
| Technique | Frequency |
|---|---|
| T1078 Valid Accounts | 1 incidents |
| T1110 Brute Force | 1 incidents |
| T1567 Exfiltration Over Web Service | 1 incidents |
Prosecution Cases Attributed to This Actor
Snowflake Enterprise Credential Stuffing & Customer Cloud Thefts
Financially motivated threat actor collective UNC5537 systematically infiltrated over 165 corporate customer tenants hosted on Snowflake (including Ticketmaster, Santander Bank, Advance Auto Parts, and LendingTree). Attackers leveraged infostealer malware logs dating back years against enterprise user accounts that lacked multi-factor authentication and IP network allowlists, exfiltrating billions of consumer records.
AT&T Cloud Telecom Call and Text Metadata Exfiltration
Illegal exfiltration of call and text interaction metadata spanning six months for approximately 110 million AT&T wireless customers. Intrusion stemmed from an illicit access point to a third-party Snowflake cloud environment, leading to a 5.7 Bitcoin extortion fee paid through an intermediary to obtain verified video evidence of dataset deletion.
Targeted Defensive Hardening for Scattered Spider / UNC5537
Primary Initial Access Defense
Enforce hardware FIDO2 multi-factor authentication across all perimeter VPN, Citrix, and cloud data portals. Prohibit SMS or push-based MFA that can be bypassed via vishing or SIM swapping.
Lateral Movement Interception
Restrict internal SMB (port 445) and RPC traversal between workstation subnets. Implement tiered Active Directory administration so domain administrator credentials are never cached on endpoints.