Threat actor · OAK-G12
OAK-G12 — Scattered Spider / UNC3944 (English-speaking financially-motivated affiliate cluster)
Description
OAK-G12 is the Scattered Spider / UNC3944 affiliate-collective: a predominantly English-speaking, predominantly Western-passport (U.S., U.K., Canada) financially-motivated cybercrime cohort that, between approximately April 2022 and the present, has been the highest-profile affiliate cluster running social-engineering-led intrusions against Western enterprise and cryptocurrency-firm targets. The cluster is genuinely distinct from prior OAK Groups along multiple axes: from OAK-G05 LockBit, OAK-G10 ALPHV / BlackCat, OAK-G11 Black Basta, and OAK-G14 Cl0p — all Russian-language operating-brand RaaS clusters — along the operating-brand-vs-affiliate-collective axis (Scattered Spider is an affiliate-collective that has used multiple RaaS-operator-brands' tooling rather than running its own RaaS infrastructure); from those same Russian-language clusters along the operator-language-and-passport axis (Scattered Spider members are predominantly English-speaking, Western-passport, and in some cases minor-or-recently-adult at time of activity); from OAK-G02 Drainer-as-a-Service along the enterprise-extortion-vs-individual-wallet-phishing axis and the value-per-incident axis (G12 affiliates execute few large-value enterprise and cryptocurrency-firm intrusions; G02 affiliates execute many small-value individual-wallet phishing extractions); and from OAK-G07 Kimsuky and OAK-G13 Iranian-crypto-operators along the commercial-criminal-vs-state-aligned axis (G12 is purely financially motivated, with no documented state-direction or state-resident-substrate). Scattered Spider's inclusion in OAK at separate-Group level — rather than as a sub-cluster of OAK-G10 ALPHV — reflects the post-2024-DOJ-indictment public-record reality that the affiliate-collective has operated against multiple RaaS brands (DragonForce, BlackCat / ALPHV, RansomHub, Qilin, multiple successor brands) and has run high-profile non-ransomware intrusions (the August 2022 Twilio / 0ktapus campaign was credential-phishing-led without a ransomware payload) such that the affiliate-cluster is a cleaner persistent identity than any single RaaS-tooling-instance.
The operational model is a social-engineering-led, MFA-bypass-heavy, identity-and-help-desk-attack intrusion style with several cluster-distinctive features. Initial-access TTPs are dominated by voice-phishing (vishing) of help-desk and IT-support staff to obtain password resets and MFA-token resets, SMS-phishing (smishing) of employees to harvest single-sign-on (Okta, Azure AD) credentials, SIM-swap attacks against high-value individuals (cryptocurrency-firm engineers, executives, and high-net-worth holders) coordinated with Western-passport accomplices at U.S. and U.K. carrier-retail outlets, and MFA-fatigue / push-notification-bombing against MFA-enrolled victims to obtain authentication-factor approval. Post-exploit TTPs include rapid lateral movement through Okta and Azure AD identity-substrate, ESXi-host-targeted ransomware deployment using whichever RaaS-affiliate tooling the cluster is currently engaged with, data-exfiltration before encryption for double-extortion negotiation, and direct cryptocurrency-firm wallet-and-custody compromise where the target is a cryptocurrency-industry firm. The cohort's operational language is English (with documented Russian-language-affiliate-cluster collaboration during the ALPHV affiliate engagement window) and the cohort communicates internally on Telegram and Discord rather than on the Russian-language criminal forums (RAMP, XSS, Exploit) that anchor the OAK-G05 / G10 / G11 / G14 cluster sets. Per Mandiant UNC3944 tracking and Microsoft Octo Tempest tracking, cluster members include teenage and recently-adult Western-passport actors with overlapping membership in the broader 'Com' / 'The Community' English-language cybercrime milieu and in adjacent SIM-swap and account-theft cohorts; the cluster's social-engineering-led operational profile is partly a function of native-English-speaker advantage in vishing U.S.-and-U.K. help-desk staff.
The cluster's defender-relevant signature is English-speaking-affiliate-collective with social-engineering-and-help-desk-attack-led intrusion style, multi-RaaS-tooling-deployment, and a 2024 DOJ-indictment-and-arrest enforcement layer that has degraded but not extinguished the cluster. The September 2023 MGM Resorts and Caesars Entertainment campaigns are the cluster's highest-profile public-record cases and made Scattered Spider the dominant affiliate cluster in the Western press for a full quarter; the August 2022 Twilio / 0ktapus campaign affected approximately 130 organisations through a single SMS-phishing-and-SSO-credential-harvesting wave and was the cluster's first widely-reported mass campaign. Cryptocurrency-industry exposure to G12 is two-fold: (1) direct cryptocurrency-firm intrusion — multiple 2022-to-2024 SIM-swap and social-engineering intrusions against cryptocurrency-firm employees, high-net-worth holders, and (per industry-forensic tracking) cryptocurrency-firm internal systems, with the July 2022 Twilio campaign producing follow-on cryptocurrency-firm impact (Coinbase notified affected users; Twilio's customer-list exposure rippled into multiple cryptocurrency firms' authentication-substrate); and (2) cryptocurrency-payment off-ramping of ransom proceeds during the cluster's RaaS-affiliate-engagement windows, with proceeds following the operating-brand's downstream laundering profile rather than a cluster-distinctive G12 profile. Defenders running anti-G12 control sets should expect substantial overlap with anti-G02 control-set design at the SIM-swap and social-engineering vector layer (where individual-wallet-phishing operators and cryptocurrency-firm-employee-targeting operators share TTPs) but should not conflate the two: G02 is high-volume individual-wallet-drain-led; G12 is low-volume large-value enterprise-and-cryptocurrency-firm-intrusion-led.
Targeting profile
OAK-G12's victim profile is enterprise-and-cryptocurrency-firm-led with sector concentration in identity-substrate vendors, telecommunications, hospitality and gaming, financial services and insurance, and consumer cryptocurrency-firm targets:
- Identity-substrate and SaaS vendors — Twilio (August 2022, the canonical 0ktapus campaign), Okta (multiple intrusions across 2022-to-2024 against Okta customer environments and against Okta's support-ticketing infrastructure), Cloudflare (August 2022, defended successfully but documented as a target), MailChimp; identity-substrate over-representation in the Scattered Spider record reflects the cluster's social-engineering-led operational profile and the high-leverage downstream effect of identity-vendor compromise.
- Telecommunications-sector firms — Twilio (Aug 2022), MicroStrategy (multiple), various U.S. and U.K. carrier-retail outlet operators as accomplice surface for the SIM-swap operational stream.
- Hospitality and gaming-sector firms — MGM Resorts (Sep 2023, the canonical case; multi-week IT-system outage and an estimated ~$100M business-interruption cost; MGM publicly refused to pay), Caesars Entertainment (Sep 2023, with reported ransom payment); both deployed via the OAK-G10 ALPHV affiliate engagement.
- Consumer-internet and software-sector firms — Reddit (Feb 2023, ALPHV-affiliate-attributed source-code-and-documents disclosure threat following an earlier phishing-led intrusion), DoorDash, Riot Games (multiple), various consumer-internet firms.
- Financial-services and insurance-sector firms — multiple large U.S. and U.K. financial-services firms across 2023-to-2025; specific named victims include Transunion, Trans-Pacific multiple-firm-cohort campaigns documented at inferred-strong per Mandiant tracking, and 2025 retail-and-financial-services campaigns against Marks & Spencer, Co-op, and Harrods (U.K.).
- Cryptocurrency-industry firms and high-net-worth individuals — multiple 2022-to-2024 SIM-swap-and-social-engineering intrusions against cryptocurrency-firm employees and high-net-worth holders; per multiple industry-forensic write-ups, several of the largest 2022-and-2023 SIM-swap-attributable cryptocurrency thefts trace to TTPs consistent with the Scattered Spider operational profile, with per-incident attribution at inferred-strong. The cluster overlaps operationally with the broader 'Com' / 'The Community' English-language SIM-swap cohort that has been responsible for high-profile individual-cryptocurrency-holder thefts across 2018-to-2025.
- Retail-and-consumer-sector firms — May-to-July 2025 U.K. retail campaigns against Marks & Spencer (multi-week e-commerce outage), Co-op, and Harrods; documented at inferred-strong per Mandiant and Microsoft tracking.
Observed Techniques
OAK v0.1's Tactic catalog is on-chain-extraction-focused; Scattered Spider's intrusion surface (off-chain social-engineering, vishing, smishing, SIM-swap, MFA-fatigue, identity-substrate compromise) sits outside that scope and is documented under external Group ID G1015 in the conventional cyber-threat-intel taxonomy. The on-chain Techniques observed in OAK-G12-attributable activity are concentrated on the cryptocurrency-firm-target post-compromise extraction surface and on the ransom-payment-laundering surface during RaaS-affiliate-engagement windows:
- OAK-T7.001 (Mixer-Routed Hop) — observed as a partial / earlier-stage component of the broader Scattered Spider laundering chain for direct-cryptocurrency-firm-intrusion proceeds, with usage of Bitcoin mixers declining across 2023-to-2024 in step with the sector-wide post-Tornado-Cash-designation decline; the cluster's English-speaking operator profile produces some divergence from the Russian-language-cluster mixer-and-off-ramp profile (more use of non-custodial-swap services, less concentration at Russian-language commercial-criminal off-ramp venues).
- OAK-T7.002 (CEX Deposit-Address Layering) — observed in both direct-cryptocurrency-firm-intrusion proceeds and in ransom-payment laundering during RaaS-affiliate engagements, with affiliate-controlled deposit-address activity at non-KYC, lax-KYC, and (in some documented cases) U.S.-or-U.K.-regulated venues used as initial layering steps; the cluster's English-speaking operator profile and Western-passport member composition produces some defender-detectable signal at regulated-venue KYC-and-onboarding controls.
- OAK-T7.003 (Cross-Asset / Cross-Chain Laundering) — observed in both intrusion-proceeds and ransom-payment laundering chains, with Bitcoin-to-stablecoin and Bitcoin-to-Monero conversion legs used as downstream layering steps.
- OAK-T8.001 (Common-Funder Cluster Reuse) — the attribution-side Technique used by Mandiant, Microsoft, Palo Alto Unit 42, Group-IB, and Chainalysis to maintain Scattered Spider affiliate-cluster identification across RaaS-tooling rotations (ALPHV → BlackCat → RansomHub → DragonForce → Qilin), across the 2024 DOJ-indictment-and-arrest enforcement layer, and across the multi-RaaS-affiliate operating-brand boundary. Distinguishing G12 affiliate-side wallet activity from the G10 / G11 / G14 operator-brand wallet activity during ransom-payment laundering chains is a non-trivial defender problem precisely because both clusters share a portion of the laundering chain; T8.001 cluster-tracking is the canonical method for partitioning the two.
- OAK-T8.002 (Cross-Chain Operator Continuity) — observed across RaaS-tooling rotations and across the 2024-to-2025 affiliate-engagement-rotation surface.
- Adjacent / pre-incident vectors not in OAK v0.1 scope: off-chain initial access via vishing of help-desk-and-IT-support staff (the canonical Scattered-Spider-distinctive vector against MGM, Caesars, and multiple subsequent victims), smishing for SSO-credential-harvesting (the canonical 0ktapus 2022 vector), SIM-swap attacks coordinated with Western-passport accomplices at carrier-retail outlets, MFA-fatigue / push-notification-bombing, identity-substrate (Okta, Azure AD) lateral movement, ESXi-host-targeted ransomware deployment, and Active-Directory-trust-relationship abuse; these are the canonical Scattered Spider intrusion vectors and are documented in the AA23-352A (CISA / FBI Scattered Spider advisory) and in multi-vendor industry-forensic tracking.
Observed Examples
Worked examples in examples/:
examples/2023-09-mgm-resorts.md— MGM Resorts help-desk-vishing intrusion deploying OAK-G10 ALPHV encryptor; canonical Scattered-Spider-distinctive social-engineering vector.examples/2023-09-caesars-entertainment.md— Caesars Entertainment paid-ransom case (~$15M) via the same affiliate stream and same week.
The high-salience public-record events anchoring the cluster (narrative — see worked examples above for the canonical entries):
- Twilio / 0ktapus campaign (August 2022). Credential-phishing campaign affecting approximately 130 organisations through a single SMS-phishing-and-SSO-credential-harvesting wave; named victims include Twilio, Cloudflare (defended), MailChimp, DoorDash, and downstream cryptocurrency-firm exposures (Twilio's customer-list exposure rippled into multiple cryptocurrency firms' authentication-substrate, with Coinbase notifying affected users) (
[groupib2022oktapus]). Attribution at confirmed at the cluster level. - MGM Resorts and Caesars Entertainment intrusions (September 2023). Help-desk-vishing-led intrusions deploying the OAK-G10 ALPHV / BlackCat encryptor; MGM publicly refused to pay and absorbed an estimated ~$100M in business-interruption costs; Caesars reported a paid ransom with a reduced disclosed-attack scope. Subsequently anchored multiple DOJ Scattered Spider indictments unsealed across 2024 (
[doj2024scatteredspider],[mandiant2023unc3944]). Attribution at confirmed at the cluster-and-named-affiliate level. - Reddit data-extortion threat (February 2023). ALPHV-affiliate-attributed claim of ~80GB of compressed source code and internal documents exfiltrated from Reddit via an earlier phishing-led employee-credential compromise; Reddit publicly stated it would not pay (cited from G10 documentation). Attribution at confirmed at the cluster level.
- CISA / FBI AA23-352A advisory (December 14, 2023). "Scattered Spider" joint cyber-security advisory characterising the cluster's TTPs across the social-engineering and identity-substrate-attack vector surface, the multi-RaaS-affiliate operating model, and the cluster's overlap with the OAK-G10 ALPHV operating brand (
[cisa2023aa23352ascatteredspider]). Attribution at confirmed at the cluster level. - DOJ five-defendant indictment (November 13, 2024). U.S. DOJ unsealing of a 14-count indictment against Ahmed Hossam Eldin Elbadawy, Noah Michael Urban, Evans Onyeaka Osiebo, Joel Martin Evans, and Tyler Robert Buchanan for wire fraud, conspiracy, and aggravated identity theft tied to the MGM Resorts and Caesars Entertainment campaigns and earlier intrusions; coordinated with U.K. NCA arrest activity (
[doj2024scatteredspider]). Attribution at confirmed at the named-defendant level. - Tyler Robert Buchanan arrest (July 2024) and extradition. Spanish National Police arrest of Buchanan in Palma de Mallorca pursuant to U.S. and U.K. extradition requests; subsequent extradition to the U.S. and federal-court appearance through 2024-and-2025. Attribution at confirmed.
- 2025 U.K. retail-sector campaigns (May-to-July 2025). Scattered-Spider-attributed intrusions against Marks & Spencer (multi-week e-commerce outage), Co-op, and Harrods, reportedly using DragonForce affiliate tooling; documented at inferred-strong per Mandiant UNC3944 tracking and Microsoft Octo Tempest tracking.
- Cryptocurrency-firm SIM-swap-and-social-engineering intrusions (2022-to-2024). Multiple high-value individual-cryptocurrency-holder SIM-swap thefts and cryptocurrency-firm-employee social-engineering intrusions consistent with the Scattered Spider operational profile per multi-vendor industry-forensic tracking; per-incident attribution at inferred-strong.
- Worked examples for specific G12-mediated cryptocurrency-firm intrusions or ransom-payment laundering flows are pending v0.x and will live under
examples/once the per-incident attribution surface stabilises sufficiently for the OAK confirmed / inferred-strong distinction.
Citations
[doj2024scatteredspider]— U.S. DOJ five-defendant indictment unsealed November 13, 2024 against Elbadawy, Urban, Osiebo, Evans, and Buchanan for wire fraud, conspiracy, and aggravated identity theft tied to Scattered Spider campaigns; referenced from G10 documentation as well.[mandiant2023unc3944]— Mandiant UNC3944 attribution write-up; referenced from G10 documentation as well.[cisa2023aa23352ascatteredspider]— Joint CISA / FBI cyber-security advisory AA23-352A on Scattered Spider TTPs, December 14, 2023.[microsoftoctotempest]— Microsoft Threat Intelligence blog on Octo Tempest activity and the multi-RaaS-affiliate operating profile.[paloaltomuddledlibra]— Palo Alto Networks Unit 42 Muddled Libra tracker write-up.[groupib2022oktapus]— Group-IB write-up of the August 2022 0ktapus / Roasted 0ktapus credential-phishing campaign affecting Twilio, Cloudflare, and approximately 130 other organisations.[krebsscatteredspider]— Krebs on Security reporting on Scattered Spider membership composition, the 'Com' / 'The Community' English-language cybercrime milieu, and the cluster's SIM-swap operational stream.[wired2023mgmcaesars]— Wired reporting on the September 2023 MGM Resorts and Caesars Entertainment intrusions.[chainalysis2025ransomware]— Chainalysis 2024-recap ransomware report (referenced from G05 / G10 / G11 documentation as well); documents Scattered Spider affiliate-engagement rotation across RaaS brands.
Discussion
On the attribution-strength split. The Scattered Spider cluster attribution is confirmed at the cluster-and-named-affiliate level — DOJ indictments unsealed across 2024 against five named defendants for the MGM Resorts and Caesars Entertainment campaigns and earlier intrusions, U.K. National Crime Agency arrests of multiple U.K.-resident members through 2024-and-2025, the December 2023 CISA / FBI AA23-352A advisory, and sustained multi-vendor industry-forensic corroboration. Attribution that specific cryptocurrency-firm intrusions or specific SIM-swap-attributable cryptocurrency thefts are downstream of a Scattered Spider placement (rather than an adjacent 'Com' / 'The Community' English-language cohort placement) is inferred-strong in most cases — multiple 2022-to-2024 cryptocurrency-firm intrusions show TTPs consistent with the Scattered Spider operational profile per Mandiant, Microsoft, and Trellix tracking, but per-incident affiliate-attribution to the named DOJ defendants requires court-filing-level evidentiary specificity that is not always publicly available. OAK contributors writing G12-attributed examples should preserve this attribution-strength split per-incident.
On why OAK-G12 is affiliate-collective rather than a sub-cluster of G10 ALPHV. Conflating Scattered Spider into G10 ALPHV — i.e., treating the September 2023 MGM and Caesars campaigns as G10-attributed rather than as G10-tooled / G12-affiliated — was a defensible early-public-record framing but is the wrong long-run structuring decision. Scattered Spider operated as an affiliate of multiple RaaS brands across the 2022-to-2025 window: the cluster used DragonForce tooling in some 2025 intrusions, RansomHub tooling after the March 2024 ALPHV exit-scam, ALPHV / BlackCat tooling for the September 2023 MGM and Caesars campaigns, and ran non-ransomware campaigns (the August 2022 0ktapus credential-phishing wave) without any RaaS-tooling deployment at all. The affiliate-collective identity is more persistent than any single RaaS-tooling-deployment instance, and the November 2024 DOJ indictments establish the cluster as an independently-tracked entity. Naming G12 as a separate Group reflects this multi-RaaS-affiliate operating reality and is parallel to the per-cluster identity principle that motivated splitting OAK-G07 from OAK-G01.
On the cluster-boundary distinction with OAK-G02 Drainer-as-a-Service. G02 (Drainer-as-a-Service) and G12 (Scattered Spider) overlap at the SIM-swap and social-engineering vector layer — both clusters target cryptocurrency holders through identity-substrate compromise — but differ along the target-class, value-per-incident, attribution-grade, and operating-model axes. G02 affiliates execute many small-value individual-wallet phishing extractions through drainer-service infrastructure under inferred-strong-grade industry-forensic attribution; G12 affiliates execute few large-value enterprise-and-cryptocurrency-firm intrusions through bespoke social-engineering tradecraft under confirmed-grade DOJ-indictment-and-arrest attribution. The two should not be conflated: a defender's anti-G02 controls (Permit2-signature warning lists, browser-extension-side phishing detection, drainer-service-infrastructure indicators-of-compromise) are partially orthogonal to anti-G12 controls (help-desk-and-IT-support staff vishing-resistance training, Okta and Azure AD identity-substrate hardening, SIM-swap-resistance controls, MFA-fatigue-resistance posture).
On the cluster-boundary distinction with OAK-G05 / G10 / G11 / G14 (Russian-language operating-brand RaaS clusters). G05, G10, G11, and G14 are all Russian-language operating-brand RaaS clusters that run ransomware-as-a-service infrastructure under principal-operator control; G12 is an affiliate-collective that has used multiple RaaS brands' tooling. Per-incident attribution during RaaS-affiliate-engagement windows requires distinguishing operator-brand wallet activity (G10 / G11 / G14 operator-side proceeds) from affiliate-side wallet activity (G12 affiliate-side proceeds); the OAK-T8.001 (Common-Funder Cluster Reuse) attribution-side Technique is the canonical method for the partition. The Change Healthcare exit-scam (documented under OAK-G10) is the canonical worked case where the operator-vs-affiliate partition becomes operationally visible on-chain; while Notchy (the affiliate in that case) is not publicly identified as a Scattered Spider member, the broader analytic principle that cluster-level wallet attribution is not the same as principal-level wallet attribution within a cluster applies symmetrically to G10-G12, G11-G12, and G14-G12 cluster boundaries.
On the cluster-boundary distinction with OAK-G07 Kimsuky and OAK-G13 Iranian-crypto-operators. G07 (Kimsuky), G13 (Iranian-crypto-operators), and G12 (Scattered Spider) are all espionage-or-financially-motivated clusters operating against Western-enterprise-and-cryptocurrency-firm targets, but differ along the state-aligned-vs-commercial-criminal axis. G07 and G13 are state-aligned (DPRK-RGB and IRGC-affiliated respectively); G12 is purely financially motivated, with no documented state-direction or state-resident-substrate. Defenders running anti-G07 / anti-G13 controls (state-aligned-actor TTP detection, espionage-target hardening, sanctions-list-aware counterparty screening) should not assume those controls cover the G12 surface, which is structurally a Western-passport-financial-crime surface rather than a state-aligned-espionage surface.
On the relationship to OAK-G03 Russian laundering infrastructure. G03 (Russian laundering infrastructure, Garantex / Grinex / A7A5 lineage) was a documented downstream venue for some fraction of Scattered Spider proceeds during the cluster's RaaS-affiliate-engagement windows (the affiliate-cut-of-ransom-payment proceeds during the OAK-G10 ALPHV affiliate engagement followed in part the broader G10-to-G03 chain). Direct-cryptocurrency-firm-intrusion proceeds during 2022-to-2024 SIM-swap-attributable cryptocurrency thefts followed a more diversified downstream profile, with non-custodial-swap services and Western-regulated-CEX deposit-address layering producing some defender-detectable signal at KYC-and-onboarding controls. Defenders running OAK-G03 watchlists should expect some overlap with G12-attributed inflows during RaaS-affiliate-engagement windows but should not expect the dense overlap they would expect with G05-attributed inflows.
On v0.x evolution. G12's 2026+ trajectory will depend on (a) whether further DOJ unsealings, U.K. NCA arrests, or international extradition-and-prosecution actions degrade the cluster further; (b) whether the affiliate-collective continues operating against successor RaaS brands beyond the current DragonForce / RansomHub / Qilin engagements; (c) whether per-incident attribution between G12 and the broader 'Com' / 'The Community' English-language cybercrime milieu becomes more cleanly resolvable as forensic providers refine sub-cluster fingerprints; and (d) whether direct-cryptocurrency-firm intrusion activity by the cluster intensifies relative to enterprise-extortion activity, possibly producing G12-anchored worked examples under examples/ for v0.x. OAK should update this entry as the public record evolves.