NEW: Group Profiler — instant APT intel lookup. Try it →

Scarlet Mimic

Overview

Scarlet Mimic is a threat group that has targeted minority rights activists. This group has not been directly linked to a government source, but the group's motivations appear to overlap with those of the Chinese government. While there is some overlap between IP addresses used by Scarlet Mimic and Putter Panda, it has not been concluded that the groups are the same.

Naming & attribution

Scarlet Mimic is tracked under 1 names across the industry. It uses 1 documented ATT&CK techniques — more than 2% of the 174 groups tracked here.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
Scarlet MimicFalcone, R. and Miller-Osborn, J.

Malware families with current indicators

One family attributed to Scarlet Mimic, carrying 1 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.

  • FakeM 1 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

Targets

Activists

Capabilities

  • Custom malware/implant development — ATT&CK: 4 attributed custom malware families

TTPs — 1 techniques across 1 tactics

Stealth

Tools & malware (4)

Psylo · MobileOrder · CallMe · FakeM

Reporting (1)