Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Scarred Manticore

Description

Scarred Manticore has been pursuing high-value targets for years, utilizing a variety of IIS-based backdoors to attack Windows servers. These include a variety of custom web shells, custom DLL backdoors, and driver-based implants.

AI Analysis

· 1 week ago

Executive Summary

Scarred Manticore is a cyber threat actor targeting high-value victims, primarily focusing on Windows servers and IIS-based backdoors. They have demonstrated advanced persistence techniques, including custom web shells and driver-based implants, which align with APT-like activity. Their operations are likely linked to broader espionage or data theft campaigns.

Goals & Targeting

Scarred Manticore appears to target sectors with high-value data, including technology, healthcare, energy, and financial services, particularly in the United States, United Kingdom, Japan, and Germany. Their strategic objectives likely involve情报收集 and data theft, targeting organizations that could provide sensitive information for economic or political gain. The actor's focus on Windows servers suggests a preference for infrastructure that is both widely used and less frequently secured against such attacks.

Enhanced Description

Scarred Manticore has emerged as a significant cyber threat actor, leveraging IIS-based backdoors to compromise Windows servers across various sectors. The actor's toolset includes custom web shells, DLL backdoors, and driver implants, which suggest a high level of technical sophistication. Linked intelligence indicates their activities are consistent with advanced persistent threat (APT) groups, potentially involved in campaigns like Cloud Hopper and Emissary Panda. Scarred Manticore's operations often involve multi-stage attacks, including initial access via phishing or exploit kits, followed by lateral movement and data exfiltration using tools such as Webmin shells and AdFind for credential dumping.

Key Capabilities

  • IIS-based backdoor implants
  • Custom web shells
  • Driver-based implants
  • Persistent access via DLL injection
  • Lateral movement using tools like AdFind
  • Credential dumping techniques

MITRE ATT&CK Tactics

Lateral Movement
Exfiltration
Privilege Escalation
Defense Evasion
Initial Access

ATT&CK Techniques

T1059.003
T1078
T1005
T1093
T1566.002

Software / Tooling

Cobalt Strike
China Chopper-web shell
Webmin-shell
AdFind
Custom RATs
Lazarus group tools

Campaigns & Victims

Scarred Manticore has been linked to multiple campaigns targeting global organizations. Their operations often involve long-term persistence, with attacks lasting several months before exfiltration begins. Notable past operations include campaigns resembling those attributed to APT29 or APT35, focusing on sectors like aerospace and defense. The group's operational tempo is methodical, with a focus on stealth and maintaining access for prolonged periods.

IOC Patterns

  • Spear-phishing emails with malicious links
  • Web shell activity (e.g., China Chopper)
  • DLL injection attempts
  • Unexpected file creation in IIS folders
  • Base64-encoded communications
  • AdFind.exe presence in logs

Recommended Actions

  • Harden IIS server configurations and regularly update software
  • Monitor for suspicious web shell activity using network sensors
  • Implement strict access controls for administrative privileges
  • Deploy Yara signatures to detect known malicious file patterns
  • Conduct regular endpoint detection exercises focusing on DLL injection
  • Enhance phishing awareness training for employees

Suggested Tags

APT
Eionage
Data Theft
Persistence
Lateral Movement

Confidence Assessment

Confidence in the Scarred Manticore's identity and TTPs is medium, as linked intelligence ties their activity to known APT campaigns. Gaps include exact motivation (state-sponsored vs. financially motivated) and specific targeting criteria.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Backdoor / C2
APT
Eionage
Data Theft
Persistence
Lateral Movement

Details

Type
Unknown
Country of Origin
I
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.