Scarlet Mimic
Overview
Scarlet Mimic is a threat group that has targeted minority rights activists. This group has not been directly linked to a government source, but the group's motivations appear to overlap with those of the Chinese government. While there is some overlap between IP addresses used by Scarlet Mimic and Putter Panda, it has not been concluded that the groups are the same.
Naming & attribution
Scarlet Mimic is tracked under 1 names across the industry. It uses 1 documented ATT&CK techniques — more than 2% of the 174 groups tracked here.
| Name | First reported by |
|---|---|
| Scarlet Mimic | Falcone, R. and Miller-Osborn, J. |
Malware families with current indicators
One family attributed to Scarlet Mimic, carrying 1 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.
- FakeM 1 indicators
Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.
Targets
Activists
Capabilities
- Custom malware/implant development — ATT&CK: 4 attributed custom malware families
TTPs — 1 techniques across 1 tactics
Stealth
-
T1036.002Right-to-Left Override
Tools & malware (4)
Psylo · MobileOrder · CallMe · FakeM
Reporting (1)
- Scarlet Mimic: Years-Long Espionage Campaign Targets Minority Activists — Falcone, R. and Miller-Osborn, J.