Scarred Manticore
Scarred Manticore has been pursuing high-value targets for years, utilizing a variety of IIS-based backdoors to attack Windows servers. These include a variety of custom web shells, custom DLL backdoors, and driver-based implants.
Scarred Manticore is a threat actor pursuing high-value targets with custom IIS backdoors, web shells, and driver-based implants.
Scarred Manticore is a threat actor that has been pursuing high-value targets for years. It primarily targets Windows servers. Their key TTPs include various IIS-based backdoors, custom web shells, custom DLL backdoors, and driver-based implants. Defenders should focus on monitoring IIS servers for anomalous activity, especially newly created web shells and suspicious DLLs.
Scarred Manticore has been pursuing high-value targets for years, utilizing a variety of IIS-based backdoors to attack Windows servers. These include a variety of custom web shells, custom DLL backdoors, and driver-based implants.
The actor uses custom IIS-based backdoors, web shells, DLL backdoors, and driver-based implants.
Defenders should focus on monitoring IIS servers for anomalous activity, especially newly created web shells and suspicious DLLs.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.