Scattered Spider reclassified as a decentralized collective of independent clusters
Threat Actor Meta
Summary
Hide ▲
Show ▼
Scattered Spider has been reclassified as a decentralized cybercrime collective, changing how its persistence and resilience are understood. The shift suggests independent clusters can keep operating even after arrests and disruption efforts hit parts of the ecosystem. The activity is associated with overlapping tactics, tools and online communities rather than a single command structure. That makes identity-based attacks, phishing and social engineering a continuing risk across affected sectors.
Related Happenings
DragonForce / Hackledorb pivots from RaaS to a formalized cartel structure
Threat Actor Meta
H score26
First: 18.06.2026 16:30
Last: 18.06.2026 16:30
Sources 1
About this happening:
Hackledorb has pivoted DragonForce from a conventional ransomware-as-a-service (RaaS) model into a formalized cartel structure, signaling a more organized and dura...
DragonForce / Hackledorb pivots from RaaS to a formalized cartel structure
Threat Actor MetaAbout this happening: Hackledorb has pivoted DragonForce from a conventional ransomware-as-a-service (RaaS) model into a formalized cartel structure, signaling a more organized and dura...
Earth Lusca Operation FishMedley espionage campaign
Campaign
H score38
First: 16.06.2026 12:44
Last: 16.06.2026 12:44
Sources 1
About this happening:
A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...
Earth Lusca Operation FishMedley espionage campaign
CampaignAbout this happening: A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...
GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations
Campaign
H score39
First: 29.05.2026 01:24
Last: 29.05.2026 01:24
Sources 1
About this happening:
GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian,...
GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations
CampaignAbout this happening: GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian,...
Webworm multi-country targeting campaign against government and enterprise victims
Campaign
H score38
First: 20.05.2026 15:51
Last: 20.05.2026 15:51
Sources 1
About this happening:
Webworm is running a multi-country targeting campaign against government agencies and enterprises, expanding the risk of persistent access across several regions. The...
Webworm multi-country targeting campaign against government and enterprise victims
CampaignAbout this happening: Webworm is running a multi-country targeting campaign against government agencies and enterprises, expanding the risk of persistent access across several regions. The...
Fake IT support Havoc campaign
Campaign
H score32
First: 03.03.2026 19:15
Last: 03.03.2026 19:15
Sources 1
About this happening:
A fake IT support campaign is using email spam, phone-based social engineering, and Havoc C2 to gain initial access, putting targeted organizations at risk of data e...
Fake IT support Havoc campaign
CampaignAbout this happening: A fake IT support campaign is using email spam, phone-based social engineering, and Havoc C2 to gain initial access, putting targeted organizations at risk of data e...
Timeline
-
07.07.2026 17:00 2 articles · 13d ago
Group-IB reclassifies Scattered Spider as a decentralized collective
Technical Analysis UpdateGroup-IB says Scattered Spider should be viewed as a decentralized cybercrime collective made up of separate clusters rather than a single gang, with no central hierarchy or shared leadership structure. The analysis says shared tactics, tools and online communities help explain why activity tied to Scattered Spider has continued despite arrests and disruption efforts, and it highlights social engineering, phishing pages impersonating Okta, Microsoft, Citrix and Google, and use of AnyDesk across clusters.
Show sources
- Scattered Spider’s Structure More Like a Cybercrime Collective Than a Unified Gang — www.infosecurity-magazine.com — 07.07.2026 17:00
- Scattered Spider’s Structure More Like a Cybercrime Collective Than a Unified Gang — www.infosecurity-magazine.com — 07.07.2026 17:00