Scarlet Mimic

Scarlet Mimic is a threat group that has targeted minority rights activists. This group has not been directly linked to a government source, but the group's motivations appear to overlap with those of the Chinese government. While there is some overlap between IP addresses used by Scarlet Mimic and Putter Panda, it has not been concluded that the groups are the same. [1]

ID: G0029
Version: 1.1

Techniques Used

Domain ID Name Use
Enterprise T1036 Masquerading

Scarlet Mimic has used the left-to-right override character in self-extracting RAR archive spearphishing attachment file names.[1]

Software

ID Name References Techniques
S0077 CallMe [1] Command-Line Interface, Exfiltration Over Command and Control Channel, Remote File Copy, Standard Cryptographic Protocol
S0076 FakeM [1] Custom Cryptographic Protocol, Data Obfuscation, Input Capture, Standard Application Layer Protocol, Standard Cryptographic Protocol
S0079 MobileOrder [1] Browser Bookmark Discovery, Data from Local System, Exfiltration Over Command and Control Channel, File and Directory Discovery, Process Discovery, Remote File Copy, Standard Cryptographic Protocol, System Information Discovery, Uncommonly Used Port
S0078 Psylo [1] Exfiltration Over Command and Control Channel, File and Directory Discovery, Remote File Copy, Standard Application Layer Protocol, Timestomp

References