Scarab APT was first spotted in 2015, but is believed to have been active since at least 2012, conducting surgical attacks against a small number of individuals across the world, including Russia and the United States. The backdoor deployed by Scarab in their campaigns is most commonly known as Scieron.
Executive Summary
Scarab is a highly sophisticated nation-state threat actor active since at least 2012, with significant operations observed as early as 2015. Known for surgical attacks targeting specific individuals and sectors in Russia and the United States, Scarab employs custom malware such as Scieron to infiltrate targets, likely for espionage or strategic data collection purposes.
Goals & Targeting
Scarab’s strategic objectives appear to align with the interests of its nation-state sponsor(s), likely targeting high-value individuals or organizations in sectors such as finance, defense, and energy. The group’s focus on surgical attacks indicates a preference for precision over volume, suggesting an intent to gather specific, sensitive information rather than conducting widespread destruction or notoriety-seeking operations.
Enhanced Description
Scarab APT is a nation-state actor first spotted in 2015 but believed to have been active since at least 2012. The group has conducted targeted attacks against individuals and organizations across the world, including high-profile targets in Russia and the U.S. Scarab's primary means of attack involves the deployment of a custom backdoor known as Scieron, which provides persistent access to compromised systems. This actor exhibits a high level of operational sophistication, focusing on discrete, highly targeted campaigns rather than broad-scale attacks. The group's modus operandi suggests a focus on intelligence gathering and espionage, with possible connections to state-sponsored activities.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Scarab has demonstrated a patient, long-term operational approach, with sustained campaigns targeting specific individuals and sectors. The group’s use of Scieron backdoor indicates an emphasis on maintaining persistence and evading detection while exfiltrating sensitive data. Notable past operations include attacks against Russian and U.S.-based targets, suggesting a focus on strategic geopolitical interests.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence inScarab's details is moderate. The actor’s identity, geographical origin, and specific campaigns remain partially unknown, though their tools and TTPs are well-documented. Further information on their exact nation-state affiliation and long-term strategic goals would enhance understanding.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics