NEW: Group Profiler — instant APT intel lookup. Try it →
Emblem illustrating the Scarlet Mimic threat group

Scarlet Mimic

Overview

Scarlet Mimic is a threat group that has targeted minority rights activists. This group has not been directly linked to a government source, but the group's motivations appear to overlap with those of the Chinese government. While there is some overlap between IP addresses used by Scarlet Mimic and Putter Panda, it has not been concluded that the groups are the same.

Naming & attribution

It uses 1 documented ATT&CK technique — more than 2% of the 174 groups tracked here.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
Scarlet MimicFalcone, R. and Miller-Osborn, J.

Targets

Activists

Capabilities

  • Custom malware/implant development — ATT&CK: 4 attributed custom malware families

TTPs — 1 technique across 1 tactic

Stealth

Tools & malware (4)

Psylo · MobileOrder · CallMe · FakeM

Reporting (1)