Scarlet Goldfinch
Scarlet Goldfinch is Red Canary’s name for an activity cluster and initial access threat first observed in June 2023. It uses compromised websites and social-engineering lures to trick users into executing malicious code. Historically, it used SocGholish-like fake browser update lures that delivered malicious JavaScript or JScript, including ZIP-delivered JScript executed by wscript.exe; in August 2024 it also used a direct-to-JS lure with the filename Update.js. In April 2025, it shifted to fake CAPTCHA / paste-and-run / ClickFix-style lures that instructed users to copy and execute malicious commands. Red Canary states Scarlet Goldfinch significantly updated its tradecraft in 2025. Its primary objective is delivery of NetSupport Manager, a legitimate remote monitoring and management tool abused for unauthorized remote access. Red Canary also reported LummaC2 as a tertiary payload, and later reporting noted Remcos as a payload in late 2025, sometimes preceding or accompanying NetSupport Manager. Other researchers have tracked Scarlet Goldfinch under the names SmartApeSG and ZPHP. Observed tradecraft includes use of JScript files to drop NetSupport Manager; compromised websites presenting fake browser update or fake CAPTCHA lures; paste-and-run chains using cmd.exe, curl.exe, PowerShell, msiexec.exe, mshta.exe, finger, and forfiles.exe; command obfuscation; use of conhost.exe to spawn nested cmd.exe processes; downloading archives masquerading as PDFs; extraction with tar -xf or rar.exe; and DLL sideloading via legitimate executables. Scarlet Goldfinch has repeatedly changed its 2025 execution chains across multiple epochs while maintaining continuity through shared C2 infrastructure, server-side web injects, and recurring later-stage payloads. Persistence observed in Scarlet Goldfinch activity includes Windows Registry Run keys, scheduled tasks, Startup-folder LNK files, and HKCU\Environment\UserInitMprLogonScript. Reported Run key examples include OFFICE, DIVXX, Support11, and progcs1. Red Canary distinguishes Scarlet Goldfinch from SocGholish because, despite similar initial lures, their post-intrusion behavior differs, especially Scarlet Goldfinch’s continued reliance on NetSupport Manager.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
Observables
28 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses compromised websites and fake browser update or paste-and-run lures to trick users into executing malicious code, leading to payload delivery including NetSupport Manager and Remcos.
A Red Canary-named threat cluster whose tradecraft was significantly updated in 2025 and which ranked as the number 6 threat in the report.
Uses malicious scripts executed from archive files as an initial access technique, with script execution followed by network activity.
Activity cluster (per Red Canary naming) that leverages compromised websites to socially engineer users into executing malicious code (notably via 'paste and run'/ClickFix/FakeCAPTCHA-style lures), leading to delivery of payloads such as remote access tooling.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.