DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 13:15:29ZSOURCES: 14CRITICAL: 18
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — wp2shell (CVE-2026-63030 + CVE-2026-60137) is being actively exploited in the wild —… /// @MsftSecIntel CRITICAL — Microsoft is tracking active exploitation of CVE-2026-63030 and CVE-2026-60137… /// @vxunderground CRITICAL — wp2shell PoCs are now floating around the internet. Public exploit code for the full… /// @FalconFeedsio CRITICAL — 🔴 Qilin ransomware group has now publicly claimed 2,035+ victims on its dark web leak… /// @TalosSecurity CRITICAL — Talos is tracking mass exploitation of wp2shell (CVE-2026-63030/CVE-2026-60137).…
18Critical Threats
18Active CVEs
10IOCs Tracked
6New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // SCATTERED-SPIDER-LAW-ENFORCEMENTFIRST SEEN: MAY 2022

SCATTERED SPIDER (Law Enforcement Update)

ALSO KNOWN AS: Octo Tempest, UNC3944, 0ktapus, Starfraud
FROM:DMZ INTELLIGENCE DESK
ORIGIN:United States, United Kingdom, Estonia (English-speaking, distributed)
ATTRIBUTION:ORGANIZED CRIME
STATUS:ACTIVE
FIRST OBSERVED:MAY 2022
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL67/100
RESOURCES67/100
PERSISTENCE70/100
STEALTH62/100
IMPACT76/100

Scattered Spider is a Western, English-speaking cybercrime collective specializing in social engineering rather than technical exploits, responsible for 100+ intrusions and $100M+ in ransom payments. In a major law enforcement development on July 1, 2026, the DOJ announced the extradition of 19-year-old Peter Stokes ('Bouquet') from Finland to face federal conspiracy, computer intrusion, and fraud charges — the latest in a sustained dismemberment campaign also including guilty pleas from UK members Thalha Jubair and Owen Flowers in June 2026, and a prior April 2026 guilty plea from Tyler Buchanan. International pressure is materially degrading the group's operational leadership roster, though the crew continues activity.

Financial extortion via social engineering, SIM swapping, and vishing; cryptocurrency theft; ransomware deployment

Help desk vishing/impersonation (T1598.004), MFA fatigue/push bombing (T1621), SIM swapping (T1586), SMS phishing (T1660), ngrok tunneling for persistent access (T1572), stolen credential abuse (T1078), data exfiltration and double extortion (T1048), cryptocurrency theft, Interpol Red Notice evasion failures

HOSPITALITY
GAMING
RETAIL
FINANCIAL SERVICES
INSURANCE
TRANSPORTATION
TECHNOLOGY

Commercial residential proxy services, ngrok tunneling, legitimate cloud storage for exfiltration, TOX/Telegram encrypted comms, dark web data leak sites, cryptocurrency mixing services

FILE DATE: JUL 2026
Peter Stokes ('Bouquet') Extradition — DOJ Prosecution
DOJ announced July 1, 2026 the extradition of 19-year-old Peter Stokes from Finland on Interpol Red Notice; charged with conspiracy, computer intrusion, and fraud linked to at least 4 intrusions including an $8M cryptocurrency ransom demand against a luxury jewelry retailer in May 2025.
FILE DATE: JUN 2026
UK Members Jubair and Flowers Guilty Pleas — TfL Attack
Thalha Jubair (20) and Owen Flowers (18) pleaded guilty in June ███████████ 2024 Transport for London hack, which caused £29 million in losses and disruption; Flowers also admitted conspiring to hack two US companies.
FILE DATE: APR 2026
Tyler Buchanan Guilty Plea — $8M Crypto Theft
Scottish ringleader Tyler Buchanan, 24, pleaded guilty in April 2026 to fraud and identity theft, admitting to stealing at least $8M in cryptocurrency via phishing campaigns targeting Twilio, LastPass, and others; faces up to 22 years in prison.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn