ScareCrow is a payload creation framework used to generate Windows malware loaders designed to evade endpoint detection and response products. It has been observed producing Go-based droppers that stage in-memory payloads, including Cobalt Strike beacons, while emphasizing defense evasion through unhooking and bypassing security tooling and by making generated binaries appear more legitimate to analysts and automated controls. Tradecraft associated with ScareCrow includes use of spoofed file metadata and Windows-like version information, and it is referenced in the context of signed or convincingly disguised executables intended to blend into normal endpoint telemetry.
Operational reporting has linked ScareCrow-generated droppers to post-compromise activity in Windows environments, where a staged loader masqueraded as legitimate enterprise software and produced a stageless Cobalt Strike payload. In that intrusion set, the loader was part of a broader campaign involving persistence, credential harvesting, keylogging, remote access, and lateral movement after initial access via trojanized software installers. Separately, the name “Scarecrow” has also appeared as the label of an apparent command-and-control panel for an otherwise unidentified backdoor in material associated with OilRig, but that usage is not sufficient to establish a confirmed malware family relationship with the ScareCrow payload framework. The strongest supported characterization is that ScareCrow is an evasive Windows loader framework used to deliver follow-on payloads during intrusion operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Update.exe was a Go based dropper created using the ScareCrow framework... resulted in the creation of a Cobalt Strike stageless payload
3 distinct techniques documented for this family, organized by ATT&CK tactic.
"if you’re building a Linux based packer (Freeze, ScareCrow, PEzor, Harriet, etc) and you want to use an icon file to blend in with the File Explorer..." and "So now you can script this out to create .res files to compile with your linux compiled malware. I know it’s not ground breaking, but it’s another piece of social engineering to help with engagements."
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A payload creation framework used to generate and deliver shellcode loaders intended to evade detection (e.g., by blending in via spoofed file attributes and code-signing, and by supporting EDR unhooking/bypass techniques).
Possible name of an unknown backdoor seen only in a screenshot of a C2 panel; the report explicitly states it was not previously observed or associated with OilRig.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.