OAK — OnChain Attack Knowledge

Worked example · 2023-09

MGM Resorts ransomware intrusion — ALPHV / Scattered Spider — 2023-09-10

Loss
approximately $100M in business-interruption costs disclosed in MGM Resorts International's October 2023 Form 8-K filing (10-day multi-property IT-system outage across casino floors, hotel-keycard systems, slot machines, and digital-services infrastructure); MGM publicly refused to pay the ransom demand. The on-chain event documented here is the attempted ransom-payment surface — MGM made no on-chain ransom payment, so this example is anchored on the negative-case (no-payment) outcome and on the cluster-attribution rather than on a payment trace.
OAK Techniques observed
OAK-T5.008 (Ransomware Extortion Payment) — the extortion-payment leg of the ransomware kill chain; none directly on-chain at the primary-event layer (MGM did not pay), but the case anchors OAK-T8.001 (Common-Funder Cluster Reuse) and OAK-T8.002 (Cross-Chain Operator Continuity) at the attribution-side layer for both OAK-G10 ALPHV and OAK-G12 Scattered Spider — wallet-funder-cluster signature continuity from prior Scattered-Spider-attributed campaigns and from broader ALPHV-affiliate-cohort wallet activity is the canonical attribution-side anchor for this case. Off-chain entry vector is help-desk vishing (out of OAK Tactic scope but documented for completeness).
Attribution
confirmed at the cluster-and-named-affiliate level. The November 13, 2024 U.S. DOJ five-defendant indictment against Ahmed Hossam Eldin Elbadawy, Noah Michael Urban, Evans Onyeaka Osiebo, Joel Martin Evans, and Tyler Robert Buchanan named MGM Resorts and Caesars Entertainment campaigns explicitly as the predicate intrusions for wire-fraud, conspiracy, and aggravated-identity-theft charges ([doj2024scatteredspider]). The CISA / FBI joint cybersecurity advisory AA23-352A "Scattered Spider" (December 14, 2023) characterises the cluster's TTPs and the multi-RaaS-affiliate operating model overlapping with ALPHV ([cisa2023aa23352ascatteredspider]). Mandiant UNC3944 attribution write-ups corroborate the affiliate-cluster identity ([mandiant2023unc3944]). Wired investigative reporting consolidates the public-record facts ([wired2023mgmcaesars]).
OAK-Gnn
OAK-G10 ALPHV / BlackCat at the operating-brand level; OAK-G12 Scattered Spider / UNC3944 at the affiliate-collective level. The MGM intrusion is the canonical worked case in the public record of the OAK-G10-by-G12-affiliate operational pattern.
Key teaching point
MGM Resorts is the canonical 2023 case of the Russian-language-RaaS-tooling × English-speaking-affiliate-collective operational pattern that anchors the OAK-G10 / OAK-G12 cluster-boundary distinction. The case demonstrates that RaaS-as-tooling (OAK-G10 ALPHV) and RaaS-as-affiliate-collective (OAK-G12 Scattered Spider) operate as independent persistent identities in the public record — Scattered Spider continued running intrusions against successor RaaS brands (RansomHub, DragonForce, Qilin) after the OAK-G10 March 2024 exit-scam terminated the ALPHV operating brand. Defender control-set design should treat the two cluster layers as orthogonal: anti-OAK-G10 controls (encryptor-strain-specific detection, ALPHV-cluster-wallet watchlist) target the operating-brand layer; anti-OAK-G12 controls (help-desk-vishing detection, identity-substrate-attack defense, English-speaking-affiliate-collective TTP coverage) target the affiliate-collective layer.

Summary

On September 10, 2023, MGM Resorts International suffered a multi-day IT-system outage across casino-floor systems, hotel-keycard systems, slot machines, digital reservations, and consumer-services infrastructure at multiple Las Vegas Strip properties (Bellagio, Aria, MGM Grand, Mandalay Bay, Cosmopolitan-MGM-managed, others). The off-chain entry vector per industry-forensic reporting and per the November 2024 DOJ indictment was help-desk-vishing of an MGM IT-support staff member by Scattered Spider / UNC3944 affiliates running the OAK-G10 ALPHV / BlackCat encryptor. The intrusion produced approximately a 10-day operational outage with manual fallback procedures (paper keycards, manual reservation handling) across multiple properties.

Per MGM's October 2023 Form 8-K filing, the company estimated approximately $100M in business-interruption cost from the incident and chose to refuse the ransom demand. No on-chain payment was made; the case therefore does not produce a payment-trace anchor and OAK records it as a negative-case (no-payment) example of an OAK-G10-by-OAK-G12 operational pattern. The case anchors OAK-G10 at the operating-brand level and OAK-G12 at the affiliate-collective level on the cluster-attribution axis rather than on the on-chain-payment-trace axis.

For OAK's purposes the case is the canonical worked example of the English-speaking-affiliate-collective running a Russian-language-RaaS-encryptor operational pattern that defines the OAK-G10 / OAK-G12 cluster-boundary distinction. Compared to OAK-G05 LockBit (where the affiliate cohort is dominantly Russian-language criminal-forum operators) the MGM case demonstrates that the RaaS-as-tooling and RaaS-as-affiliate-collective layers can have different operator-language-and-passport profiles, and that defender control-set design needs to assume both layers are operative.

Timeline (UTC)

When Event OAK ref
2023-09-10 onward Help-desk-vishing of MGM IT-support staff member by Scattered Spider affiliates; ALPHV / BlackCat encryptor deployed (off-chain entry vector — out of OAK Tactic scope) (off-chain entry)
2023-09-10 to 2023-09-20 ~10-day multi-property IT-system outage across MGM Las Vegas Strip properties; paper-keycard and manual-reservation fallback in operation (off-chain operational impact)
2023-09-14 Caesars Entertainment publicly discloses parallel intrusion with reported ransom payment — see examples/2023-09-caesars-entertainment.md (parallel cluster activity)
2023-10 MGM Resorts International Form 8-K filing estimates ~$100M in business-interruption cost; MGM publicly refuses to pay No-payment outcome on the negative-case axis
2023-12-14 CISA / FBI joint cybersecurity advisory AA23-352A "Scattered Spider" issued ([cisa2023aa23352ascatteredspider]) (cluster-attribution document)
2024-07 Tyler Robert Buchanan arrested in Palma de Mallorca by Spanish National Police pursuant to U.S. and U.K. extradition requests (named-defendant arrest)
2024-11-13 U.S. DOJ unsealed five-defendant indictment naming MGM and Caesars campaigns as predicate intrusions ([doj2024scatteredspider]) Named-defendant attribution at confirmed

What defenders observed

  • Help-desk-vishing as primary initial-access vector. The MGM intrusion is the canonical 2023 case of help-desk social-engineering as the principal RaaS-affiliate initial-access vector. Per the CISA AA23-352A advisory and Mandiant UNC3944 tracking, the Scattered Spider / UNC3944 affiliate cohort's English-speaking operator profile produces native-speaker advantage in vishing U.S.-and-U.K. help-desk staff — a profile materially different from the Russian-language-affiliate-cohort vector profile (exploitation-of-public-facing-vulnerabilities, exposed-RDP, exposed-VPN-without-MFA) that dominates the broader RaaS-affiliate landscape.
  • No-payment outcome and the disclosure-cost trade-off. MGM's choice to refuse payment incurred approximately $100M in business-interruption cost; Caesars's parallel choice to pay incurred a smaller direct dollar cost (~$15M reported) but produced different downstream sectoral-disclosure dynamics. The MGM-vs-Caesars contrast is the canonical 2023 case in the public record of paired victim-pay-vs-no-pay decision outcomes for parallel intrusions by the same affiliate-collective in the same week and is widely cited in incident-response and CISO-decision-making literature.
  • Multi-RaaS-affiliate operating model. Scattered Spider's operational pattern of running intrusions against multiple RaaS-tooling brands (ALPHV in 2023, RansomHub from 2024 onward, DragonForce / Qilin in 2025) means that defender attribution against the affiliate-collective surface can produce confirmed-grade attribution at the OAK-G12 layer that survives RaaS-tooling-rotation events. Defender control-set design should treat OAK-G12 as a persistent identity across RaaS-tooling rotations.
  • Negative-case attribution anchoring. Even without an on-chain payment, the MGM case anchors OAK-G10 and OAK-G12 at confirmed-grade attribution because the November 2024 DOJ indictment named the campaigns explicitly. Future OAK content should not require an on-chain payment trace to anchor a Group-attribution case at confirmed-grade — court-filing-and-OFAC-designation-level attribution is sufficient.

What this example tells contributors writing future Technique pages

  • No-payment outcomes are valid OAK examples. Examples without on-chain payment traces but with strong cluster attribution at the indictment-and-advisory layer are valid Group-attribution anchors in the OAK corpus. The MGM case anchors OAK-G10 and OAK-G12 at confirmed-grade despite the absence of an on-chain payment trace. Future Group-attribution examples should not be excluded for lack of payment trace if the indictment-and-advisory attribution layer is sufficient.
  • The Russian-language-RaaS-tooling × English-speaking-affiliate-collective pattern is a sustained operating model. Future RaaS-attributed examples should expect that the operating-brand language profile and the affiliate-collective language profile may differ; OAK content should mark this distinction explicitly when both layers are operative, rather than collapsing them into a single language-or-passport attribution.
  • The paired-victim-decision contrast (MGM-pay-no vs Caesars-pay-yes) is a structural OAK observation. Defender control-set design and OAK contributor framing should treat the pay-vs-no-pay decision as a structurally observable downstream outcome of the same upstream cluster intrusion, not as evidence of different upstream cluster activity. The companion example at examples/2023-09-caesars-entertainment.md documents the parallel pay-yes outcome.

Public references

  • [doj2024scatteredspider] — U.S. DOJ five-defendant indictment unsealed November 13, 2024 against Elbadawy, Urban, Osiebo, Evans, and Buchanan for wire fraud, conspiracy, and aggravated identity theft tied to MGM Resorts and Caesars Entertainment campaigns.
  • [cisa2023aa23352ascatteredspider] — Joint CISA / FBI cybersecurity advisory AA23-352A on Scattered Spider TTPs, December 14, 2023.
  • [mandiant2023unc3944] — Mandiant UNC3944 attribution write-up.
  • [wired2023mgmcaesars] — Wired investigative reporting on the MGM and Caesars intrusions and the Scattered Spider / ALPHV operational pattern.
  • [microsoftoctotempest] — Microsoft Threat Intelligence on Octo Tempest activity and the multi-RaaS-affiliate operating profile.
  • [paloaltomuddledlibra] — Palo Alto Networks Unit 42 Muddled Libra tracker write-up.

Discussion

MGM Resorts is the canonical 2023 case of the Russian-language-RaaS-tooling × English-speaking-affiliate-collective operational pattern that anchors the OAK-G10 / OAK-G12 cluster-boundary distinction. The case demonstrates that RaaS-as-tooling (OAK-G10 ALPHV) and RaaS-as-affiliate-collective (OAK-G12 Scattered Spider) operate as independent persistent identities in the public record — Scattered Spider continued running intrusions against successor RaaS brands (RansomHub, DragonForce, Qilin) after the OAK-G10 March 2024 exit-scam terminated the ALPHV operating brand. Defender control-set design should treat the two cluster layers as orthogonal: anti-OAK-G10 controls (encryptor-strain-specific detection, ALPHV-cluster-wallet watchlist) target the operating-brand layer; anti-OAK-G12 controls (help-desk-vishing detection, identity-substrate-attack defense, English-speaking-affiliate-collective TTP coverage) target the affiliate-collective layer.

The MGM case also illustrates that negative-case (no-payment) outcomes are first-class OAK examples. The case has no on-chain payment trace, but the cluster-attribution at the November 2024 DOJ indictment layer is confirmed-grade and the off-chain operational impact (~$100M in business-interruption cost) is on the public record. OAK contributors should not require an on-chain payment trace to anchor a Group-attribution case if the indictment-and-advisory attribution is sufficient. The companion Caesars Entertainment example (examples/2023-09-caesars-entertainment.md) documents the parallel pay-yes outcome and provides the on-chain-payment-trace anchor for the same upstream cluster activity.

Techniques demonstrated (3)