Scarlet Mimic is a cyberespionage threat actor targeting Tibetan and Uyghur communities, activists, journalists, non-governmental organizations, and their supporters. Its targeting has also included government agencies in India and Russia. Its operations encompass Windows malware delivery, credential phishing, and sustained Android surveillance. Documented campaigns against Tibetan organizations date to at least 2013, while its MobileOrder Android spyware campaign operated from 2015 through at least August 2022. The group uses tailored spearphishing messages that impersonate trusted activists, officials, and organizational representatives. Windows campaigns have delivered the FakeM malware family, including FakeM Custom SSL, through malicious documents exploiting vulnerabilities such as CVE-2012-0158 and CVE-2010-3333. It has also used counterfeit Google login pages to steal credentials, redirecting victims to relevant decoy material afterward. Scarlet Mimic is associated with right-to-left override abuse to disguise malicious files. MobileOrder applications masquerade as Uyghur-themed documents, images, or audio and display decoy content while conducting background surveillance. Their capabilities include collecting messages, contacts, call logs, browser history, files, and location data; recording calls and ambient audio; taking photographs and screenshots; executing remote shell commands; and installing additional applications. Some variants request device-administrator and root privileges, hide their application icons, and maintain persistence through background services and Android broadcast triggers. The malware uses encrypted command-and-control communications and can retrieve server information through dead-drop resolvers. Operators can also send messages or place calls from compromised devices and delete associated records.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
Carefully crafted email lures are sent to targets carrying exploits that leverage well-known vulnerabilities (e.g., CVE-2012-0158, CVE-2010-3333), which we have seen used in campaigns against Tibetan groups frequently in recent years.
Carefully crafted email lures are sent to targets carrying exploits that leverage well-known vulnerabilities (e.g., CVE-2012-0158, CVE-2010-3333), which we have seen used in campaigns against Tibetan groups frequently in recent years.
81 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with the Right-to-Left Override (RTLO) defense evasion technique to disguise malicious files.
Mentioned as a possible but unconfirmed actor potentially connected to the JadeRAT surveillanceware family.
Long-running espionage campaigns targeting the Tibetan community, including Tibetan activists, journalists, NGOs, and also Uyghur groups; the group shifted from document-based malware operations to credential phishing using repurposed command-and-control infrastructure.
Referenced as a threat actor associated with use of the Right-to-Left Override (RTLO) technique for defense evasion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.