Pillaraxis Cyber law, privacy & security — read plainly
Vol. 2 · 2026
Kochi, India
Brief No. 018
Incident Reports

Scattered Spider, DragonForce, and the Rise of Ransomware-as-a-Service

The group behind the M&S attack doesn't write its own ransomware. It rents it — and the platform it rents from offers affiliates an 80% cut.

'Scattered Spider' is not a single organisation with a fixed membership, a leadership structure, or even a settled name — security researchers track the same cluster of activity under half a dozen labels, including UNC3944, Octo Tempest, and Muddled Libra, depending on which vendor is doing the naming. What unites the activity under all those labels is a consistent playbook built almost entirely around social engineering rather than technical exploitation: phone calls to help desks impersonating employees, SIM-swapping to hijack a target's phone number, MFA fatigue attacks that spam a user with authentication prompts until one gets approved by accident, and convincing replica login pages.

What Scattered Spider does not do, typically, is write its own ransomware. Instead it works as an affiliate of whichever ransomware-as-a-service platform currently offers the best terms — moving from ALPHV/BlackCat, before that group disbanded in early 2024, through RansomHub and Qilin, before settling on DragonForce as the platform used in the M&S attack. DragonForce, which launched in late 2023, functions less like a criminal gang and more like a software vendor: it offers affiliates roughly 80 percent of any ransom collected, along with automated tooling for managing negotiations and extortion, in exchange for a cut of the proceeds.

The M&S breach was already won before any ransomware was deployed. Ransomware-as-a-service has industrialised the back half of the attack — the front half is still human.

This division of labour is the structural reason ransomware has scaled the way it has. An attacker does not need to develop encryption malware, build a leak site, or design a ransom negotiation workflow — all of that exists as a rentable service. What an affiliate needs is the social engineering skill to get an initial foothold, which is precisely the skill Scattered Spider has specialised in. Some ransomware operators have even begun offering victims access to in-house legal teams and PR staff during negotiations, formalising extortion into something closer to a business process than a smash-and-grab crime.

For defenders, the practical implication is that the malware itself is rarely the interesting part of these attacks, and rarely the part worth the most defensive investment. The M&S breach succeeded entirely before any ransomware was deployed — the moment the help desk operator reset that credential, the outcome was largely determined. Ransomware-as-a-service has industrialised the back half of the attack chain. It has made the front half, the human one, the part still worth defending.

← OlderDORA Turns Real: What 2026 Enforcement Actually Means for Financial Institutions