Scarab APT is a threat actor of unknown origin known for targeted cyber espionage using the Scieron backdoor against high-value individuals.
Analyst brief
Scarab APT is a threat actor of unknown origin that has been conducting surgical attacks against specific individuals in Russia, Ukraine, and the United States since at least 2012. The group primarily leverages a custom backdoor known as Scieron to carry out targeted cyber espionage operations against a small number of high-value targets. Key TTPs include initial access via highly tailored spear-phishing emails or social engineering, followed by the deployment of the Scieron backdoor for persistent C2 communication. Defenders should focus on monitoring for suspicious spear-phishing campaigns aimed at key personnel, scrutinizing network traffic for Scieron-related C2 patterns, and actively hunting for indicators associated with this backdoor in their boundary defenses.
Scarab
unknown
Scarab APT was first spotted in 2015, but is believed to have been active since at least 2012, conducting surgical attacks against a small number of individuals across the world, including Russia and the United States. The backdoor deployed by Scarab in their campaigns is most commonly known as Scieron.
How does the Scarab APT group gain initial access to its victims?+
The group typically gains initial access via highly tailored spear-phishing emails or advanced social engineering techniques aimed at high-value individuals.
What specific malware does Scarab APT use in its operations?+
Scarab APT uses a custom backdoor known as Scieron to carry out targeted cyber espionage operations.