Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Scarab

Description

Scarab APT was first spotted in 2015, but is believed to have been active since at least 2012, conducting surgical attacks against a small number of individuals across the world, including Russia and the United States. The backdoor deployed by Scarab in their campaigns is most commonly known as Scieron.

AI Analysis

· 1 week ago

Executive Summary

Scarab is a highly sophisticated nation-state threat actor active since at least 2012, with significant operations observed as early as 2015. Known for surgical attacks targeting specific individuals and sectors in Russia and the United States, Scarab employs custom malware such as Scieron to infiltrate targets, likely for espionage or strategic data collection purposes.

Goals & Targeting

Scarab’s strategic objectives appear to align with the interests of its nation-state sponsor(s), likely targeting high-value individuals or organizations in sectors such as finance, defense, and energy. The group’s focus on surgical attacks indicates a preference for precision over volume, suggesting an intent to gather specific, sensitive information rather than conducting widespread destruction or notoriety-seeking operations.

Enhanced Description

Scarab APT is a nation-state actor first spotted in 2015 but believed to have been active since at least 2012. The group has conducted targeted attacks against individuals and organizations across the world, including high-profile targets in Russia and the U.S. Scarab's primary means of attack involves the deployment of a custom backdoor known as Scieron, which provides persistent access to compromised systems. This actor exhibits a high level of operational sophistication, focusing on discrete, highly targeted campaigns rather than broad-scale attacks. The group's modus operandi suggests a focus on intelligence gathering and espionage, with possible connections to state-sponsored activities.

Key Capabilities

  • Custom malware development (Scieron backdoor)
  • Spear-phishing campaigns
  • Persistent network access and data exfiltration
  • Geopolitical targeting
  • Sophisticated TTPs for avoiding detection

MITRE ATT&CK Tactics

Espionage
Data Theft and Exfiltration
Persistence

ATT&CK Techniques

T1059.003
T1233
T1185
T1490
T1566.001

Software / Tooling

Scieron Backdoor
Custom Spear-Phishing Tools
Malware Development Frameworks

Campaigns & Victims

Scarab has demonstrated a patient, long-term operational approach, with sustained campaigns targeting specific individuals and sectors. The group’s use of Scieron backdoor indicates an emphasis on maintaining persistence and evading detection while exfiltrating sensitive data. Notable past operations include attacks against Russian and U.S.-based targets, suggesting a focus on strategic geopolitical interests.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • C2 communication via custom protocols or domains
  • Use of domain generation algorithms for persistence
  • Custom payloads dropped during initial access

Recommended Actions

  • Implement advanced email filtering to detect spear-phishing attempts.
  • Monitor network traffic for signs of C2 communication channels.
  • Conduct regular endpoint detection and response (EDR) scans.

Suggested Tags

APT
Nation-State
Cyber-Espionage
Targeted Attacks

Confidence Assessment

Confidence inScarab's details is moderate. The actor’s identity, geographical origin, and specific campaigns remain partially unknown, though their tools and TTPs are well-documented. Further information on their exact nation-state affiliation and long-term strategic goals would enhance understanding.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Backdoor / C2
Nation-State
Cyber-Espionage
Targeted Attacks

Details

Type
Nation-State
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.