Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
6 malware families

Scarlet Goldfinch

Also known asScarlet Goldfinch

Scarlet Goldfinch is Red Canary’s name for an activity cluster and initial access threat first observed in June 2023. It uses compromised websites and social-engineering lures to trick users into executing malicious code. Historically, it used SocGholish-like fake browser update lures that delivered malicious JavaScript or JScript, including ZIP-delivered JScript executed by wscript.exe; in August 2024 it also used a direct-to-JS lure with the filename Update.js. In April 2025, it shifted to fake CAPTCHA / paste-and-run / ClickFix-style lures that instructed users to copy and execute malicious commands. Red Canary states Scarlet Goldfinch significantly updated its tradecraft in 2025. Its primary objective is delivery of NetSupport Manager, a legitimate remote monitoring and management tool abused for unauthorized remote access. Red Canary also reported LummaC2 as a tertiary payload, and later reporting noted Remcos as a payload in late 2025, sometimes preceding or accompanying NetSupport Manager. Other researchers have tracked Scarlet Goldfinch under the names SmartApeSG and ZPHP. Observed tradecraft includes use of JScript files to drop NetSupport Manager; compromised websites presenting fake browser update or fake CAPTCHA lures; paste-and-run chains using cmd.exe, curl.exe, PowerShell, msiexec.exe, mshta.exe, finger, and forfiles.exe; command obfuscation; use of conhost.exe to spawn nested cmd.exe processes; downloading archives masquerading as PDFs; extraction with tar -xf or rar.exe; and DLL sideloading via legitimate executables. Scarlet Goldfinch has repeatedly changed its 2025 execution chains across multiple epochs while maintaining continuity through shared C2 infrastructure, server-side web injects, and recurring later-stage payloads. Persistence observed in Scarlet Goldfinch activity includes Windows Registry Run keys, scheduled tasks, Startup-folder LNK files, and HKCU\Environment\UserInitMprLogonScript. Reported Run key examples include OFFICE, DIVXX, Support11, and progcs1. Red Canary distinguishes Scarlet Goldfinch from SocGholish because, despite similar initial lures, their post-intrusion behavior differs, especially Scarlet Goldfinch’s continued reliance on NetSupport Manager.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

8 of 15 tactics34 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
2 techniques
T1189×3
Drive-by Compromise
T1566
Phishing
TA0002
Execution
4 techniques
T1047
Windows Management Instrumentation
T1053
Scheduled Task/Job
T1053.005×3
Scheduled Task
T1059
Command and Scripting Interpreter
T1059.001×4
PowerShell
T1059.003×4
Windows Command Shell
T1059.005×3
Visual Basic
T1059.007×3
JavaScript
T1204×2
User Execution
T1204.002×4
Malicious File
T1204.004×2
Malicious Copy and Paste
TA0003
Persistence
2 techniques
T1053
Scheduled Task/Job
T1053.005×3
Scheduled Task
T1547
Boot or Logon Autostart Execution
T1547.001×3
Registry Run Keys / Startup Folder
T1547.009
Shortcut Modification
TA0004
Privilege Escalation
2 techniques
T1053
Scheduled Task/Job
T1053.005×3
Scheduled Task
T1547
Boot or Logon Autostart Execution
T1547.001×3
Registry Run Keys / Startup Folder
T1547.009
Shortcut Modification
TA0005
Stealth
3 techniques
T1027×4
Obfuscated Files or Information
T1036
Masquerading
T1218×2
System Binary Proxy Execution
T1218.005×2
Mshta
T1218.007
Msiexec
TA0008
Lateral Movement
1 technique
T1021
Remote Services
T1021.005
VNC
TA0009
Collection
1 technique
T1560
Archive Collected Data
TA0011
Command and Control
3 techniques
T1071
Application Layer Protocol
T1105×4
Ingress Tool Transfer
T1219
Remote Access Tools
IOCS

Observables

28 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping24

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal6

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables28

Domains, IPs, and hashes tied to this actor, refreshed continuously.