Scarlet Mimic

Scarlet Mimic is a threat group that has targeted minority rights activists. This group has not been directly linked to a government source, but the group's motivations appear to overlap with those of the Chinese government. While there is some overlap between IP addresses used by Scarlet Mimic and Putter Panda, it has not been concluded that the groups are the same. [1]

ID: G0029
Version: 1.1

Techniques Used

DomainIDNameUse
EnterpriseT1036MasqueradingScarlet Mimic has used the left-to-right override character in self-extracting RAR archive spearphishing attachment file names.[1]

Software

IDNameReferencesTechniques
S0077CallMe[1]Command-Line Interface, Exfiltration Over Command and Control Channel, Remote File Copy, Standard Cryptographic Protocol
S0076FakeM[1]Custom Cryptographic Protocol, Data Obfuscation, Input Capture, Standard Application Layer Protocol, Standard Cryptographic Protocol
S0079MobileOrder[1]Browser Bookmark Discovery, Data from Local System, Exfiltration Over Command and Control Channel, File and Directory Discovery, Process Discovery, Remote File Copy, Standard Cryptographic Protocol, System Information Discovery, Uncommonly Used Port
S0078Psylo[1]Exfiltration Over Command and Control Channel, File and Directory Discovery, Remote File Copy, Standard Application Layer Protocol, Timestomp

References