Scarlet Mimic is a long-running cyber-espionage threat actor associated with surveillance and credential-phishing operations against Tibetan and Uyghur communities and related organizations. The group has also been reported targeting government entities in India and Russia. Scarlet Mimic is widely known for using socially engineered lures tied to regional political, cultural, and activist themes, and for operating both desktop and mobile surveillance campaigns over multiple years. Scarlet Mimic has been linked to malware delivery through spearphishing documents exploiting older Microsoft Office vulnerabilities including CVE-2012-0158 and CVE-2010-3333, as well as use of the FakeM malware family, including the FakeM Custom SSL variant. Later activity showed a shift toward credential phishing, with infrastructure previously used for malware operations repurposed to host fake Google login pages aimed at Tibetan journalists, activists, and NGOs. These phishing operations used highly tailored decoy content relevant to Tibetan political and community issues in order to steal account credentials while minimizing suspicion. The actor has also been tied to a sustained Android surveillance campaign using the MobileOrder spyware family, active since at least 2015 and continuing through 2022. In these operations, trojanized Android applications masqueraded as Uyghur-themed documents, images, or audio content and were distributed outside official app stores through social engineering. Once installed, MobileOrder conducted extensive device surveillance, including theft of device information, messages, call logs, files, browser history, and location data; screenshot capture; photo capture; call recording; ambient audio recording; remote shell access; and installation or removal of additional applications. Some variants sought elevated privileges such as device administrator or root access, hid their presence, and used keepalive mechanisms and multiple Android event triggers to maintain persistence. Scarlet Mimic-linked mobile tooling has used encrypted command-and-control communications, dead-drop resolvers, and evolving location-tracking methods, reflecting sustained operational maintenance and adaptation. The actor has also been associated with defense-evasion behavior such as Right-to-Left Override filename or process masquerading. Possible links have been discussed between Scarlet Mimic and other regional espionage actors, but such relationships remain unconfirmed. The overall pattern is consistent with a politically motivated espionage actor focused on long-term surveillance of ethnic minorities, activists, journalists, and associated civil-society targets, particularly in the China-related regional context.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
Carefully crafted email lures are sent to targets carrying exploits that leverage well-known vulnerabilities (e.g., CVE-2012-0158, CVE-2010-3333), which we have seen used in campaigns against Tibetan groups frequently in recent years.
Carefully crafted email lures are sent to targets carrying exploits that leverage well-known vulnerabilities (e.g., CVE-2012-0158, CVE-2010-3333), which we have seen used in campaigns against Tibetan groups frequently in recent years.
81 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with the Right-to-Left Override (RTLO) defense evasion technique to disguise malicious files.
Mentioned as a possible but unconfirmed actor potentially connected to the JadeRAT surveillanceware family.
Long-running espionage campaigns targeting the Tibetan community, including Tibetan activists, journalists, NGOs, and also Uyghur groups; the group shifted from document-based malware operations to credential phishing using repurposed command-and-control infrastructure.
Referenced as a threat actor associated with use of the Right-to-Left Override (RTLO) technique for defense evasion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.