Scieron is a custom backdoor/Trojan associated with the Scarab threat actor. Public reporting cited in the provided content describes Scarab as active since at least 2012 and publicly identified since 2015, with moderate-confidence assessment that it is a Chinese-speaking espionage actor. Scieron is described as a custom backdoor used by Scarab in multiple campaigns and may be the predecessor to the HeaderTip malware.
The content links Scieron to Scarab through historical campaign reporting and shared infrastructure. SentinelLabs reported overlap between a 2018 Scieron sample (SHA1: 121ea06f391d6b792b3e697191d69dc500436604) and infrastructure also used by HeaderTip, including the C2 server dynamic.ddns[.]mobi. The same reporting assessed with high confidence that activity tracked as UAC-0026 was linked to Scarab, based in part on malware design similarities and infrastructure reuse between HeaderTip and earlier Scieron activity.
Separate Unit 42 reporting noted infrastructure overlap between Bookworm operations and servers hosting command-and-control for FFRAT, PlugX, Poison Ivy, and Scieron, suggesting the same threat actors used Scieron among a broader payload set. In that reporting, Bookworm campaigns primarily targeted Thai government entities from at least mid-2015 and used spear-phishing with decoy files themed around Thai current events; however, the content only supports that Scieron shared infrastructure with those operations, not that Scieron itself was definitively delivered by the same lures.
High-confidence characteristics directly supported by the content are limited: Scieron is a Trojan/backdoor, it has command-and-control infrastructure overlap with other malware families, it is associated with Scarab, and it appears to have been used in espionage-oriented campaigns involving geopolitical targeting. No additional verified technical details, persistence mechanisms, or standalone infection chain specific to Scieron are directly provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Scarab has conducted a number of campaigns over the years, making use of a custom backdoor originally known as Scieron, which may be the predecessor to HeaderTip.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom backdoor associated with Scarab and described as a likely predecessor to HeaderTip. It is linked through reused infrastructure and earlier Scarab operations.
A custom backdoor historically associated with Scarab and assessed as a likely predecessor to HeaderTip. The report links Scieron and HeaderTip through malware design similarities and reused C2 infrastructure.
A trojan family observed in related infrastructure connected to the Bookworm campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.