Scarlet Goldfinch is an activity cluster and initial-access threat first observed in mid-2023. It is primarily associated with compromised websites and social-engineering lures that trick users into executing malicious code, initially through fake browser update prompts and later through paste-and-run or fake CAPTCHA workflows. The cluster is tracked as distinct from SocGholish despite similarities in lure style and early-stage delivery, because its downstream behavior and payloading patterns differ. Other reporting has associated this cluster with the names SmartApeSG and ZPHP. Scarlet Goldfinch historically used JavaScript-based delivery chains, including JScript executed by the Windows script host, to install NetSupport Manager, a legitimate remote monitoring and management tool abused for unauthorized remote access. Early observed chains used ZIP-delivered scripts and follow-on batch or VBS stages; later activity shifted to obfuscated PowerShell. The cluster has consistently used NetSupport Manager as its principal payload, while additional follow-on payloads reported across different periods include LummaC2, Remcos, StealC, and ArechClient2. In 2025 the cluster significantly evolved its tradecraft and became strongly associated with malicious copy-and-paste execution. Across multiple operational phases, it repeatedly changed command syntax, download methods, and LOLBAS usage while preserving continuity through shared infrastructure and recurring payload patterns. Observed tooling and execution methods included cmd, PowerShell, curl, msiexec, mshta, finger, forfiles, WMI-based process creation, archive extraction utilities, and DLL sideloading. The actor also used command obfuscation, delayed environment variable expansion, nested shell execution, and other detection-evasion measures. Persistence mechanisms attributed to Scarlet Goldfinch include Registry Run keys, scheduled tasks, Startup-folder shortcuts, and UserInitMprLogonScript abuse. The cluster’s operations are notable for blending into enterprise environments through abuse of legitimate administration software, especially NetSupport Manager, which can facilitate sustained remote control and enable further payload delivery. Scarlet Goldfinch is best characterized as a flexible initial-access and delivery cluster focused on establishing footholds through user execution and then deploying remote-access tooling for post-compromise operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
28 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Activity cluster using compromised websites to trick users into executing malicious code, associated in the article with ClickFix-style activity.
Uses compromised websites and fake browser update or paste-and-run lures to trick users into executing malicious code, leading to payload delivery including NetSupport Manager and Remcos.
A Red Canary-named threat cluster whose tradecraft was significantly updated in 2025 and which ranked as the number 6 threat in the report.
Uses malicious scripts executed from archive files as an initial access technique, with script execution followed by network activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.