Trusted Design

Scarlet Mimic: Espionage Campaign Targets Minority Activists

概要

Over the past seven months, Unit 42 has been investigating a series of attacks we attribute to a group we have code named “Scarlet Mimic.” The attacks began over four years ago and their targeting pattern suggests that this adversary’s primary mission is to gather information about minority rights activists. We do not have evidence directly linking these attacks to a government source, but the information derived from these activities supports an assessment that a group or groups with motivations similar to the stated position of the Chinese government in relation to these targets is involved. The attacks we attribute to Scarlet Mimic have primarily targeted Uyghur and Tibetan activists as well as those who are interested in their causes. Both the Tibetan community and the Uyghurs, a Turkic Muslim minority residing primarily in northwest China, have been targets of multiple sophisticated attacks in the past decade.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Fox Kitten

Score: 5.38
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1036.004 - Masquerade Task or Service
MITREへのリンク →

Volt Typhoon

Score: 6.44
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1069.001 - Local Groups
MITREへのリンク →

APT38

Score: 4.65
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1204.001 - Malicious Link
MITREへのリンク →

Scattered Spider

Score: 6.21
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1219.002 - Remote Desktop Software
MITREへのリンク →

Moonstone Sleet

Score: 9.65
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1587 - Develop Capabilities
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Chimera

Score: 6.44
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1069.001 - Local Groups
MITREへのリンク →

Kimsuky

Score: 12.63
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1102.002 - Bidirectional Communication
  • T1219.002 - Remote Desktop Software
  • T1587 - Develop Capabilities
  • T1204.001 - Malicious Link
MITREへのリンク →

Carbanak

Score: 4.49
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

FIN7

Score: 5.85
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
MITREへのリンク →

APT32

Score: 3.46
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1204.001 - Malicious Link
MITREへのリンク →

Winter Vivern

Score: 3.46
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1204.001 - Malicious Link
MITREへのリンク →

Wizard Spider

Score: 7.59
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1552.006 - Group Policy Preferences
  • T1204.001 - Malicious Link
MITREへのリンク →

FIN6

Score: 4.62
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

PROMETHIUM

Score: 6.23
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1205.001 - Port Knocking
MITREへのリンク →

UNC3886

Score: 6.23
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1205.001 - Port Knocking
MITREへのリンク →

ZIRCONIUM

Score: 5.85
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
MITREへのリンク →

Magic Hound

Score: 8.38
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Lazarus Group

Score: 7.02
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1102.002 - Bidirectional Communication
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Storm-0501

Score: 5.02
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1219.002 - Remote Desktop Software
MITREへのリンク →

APT33

Score: 5.49
Matched TTPs:
  • T1552.006 - Group Policy Preferences
  • T1204.001 - Malicious Link
MITREへのリンク →

Turla

Score: 6.91
Matched TTPs:
  • T1069.001 - Local Groups
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
MITREへのリンク →

Tonto Team

Score: 3.15
Matched TTPs:
  • T1069.001 - Local Groups
MITREへのリンク →

HEXANE

Score: 5.55
Matched TTPs:
  • T1069.001 - Local Groups
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

admin@338

Score: 3.15
Matched TTPs:
  • T1069.001 - Local Groups
MITREへのリンク →

OilRig

Score: 7.03
Matched TTPs:
  • T1069.001 - Local Groups
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

APT39

Score: 3.76
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
MITREへのリンク →

Sandworm Team

Score: 3.76
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
MITREへのリンク →

APT28

Score: 8.30
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1498 - Network Denial of Service
  • T1204.001 - Malicious Link
MITREへのリンク →

MuddyWater

Score: 3.76
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
MITREへのリンク →

Gamaredon Group

Score: 3.76
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
MITREへのリンク →

APT29

Score: 8.42
Matched TTPs:
  • T1562.008 - Disable or Modify Cloud Logs
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Contagious Interview

Score: 10.66
Matched TTPs:
  • T1219.002 - Remote Desktop Software
  • T1587 - Develop Capabilities
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Evilnum

Score: 4.29
Matched TTPs:
  • T1219.002 - Remote Desktop Software
  • T1204.001 - Malicious Link
MITREへのリンク →

Storm-1811

Score: 5.45
Matched TTPs:
  • T1219.002 - Remote Desktop Software
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Mustang Panda

Score: 4.29
Matched TTPs:
  • T1219.002 - Remote Desktop Software
  • T1204.001 - Malicious Link
MITREへのリンク →

Equation

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

Strider

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

Windshift

Score: 3.88
Matched TTPs:
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

EXOTIC LILY

Score: 3.88
Matched TTPs:
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Kimsuky

Score: 0.82
Matched TTPs:
  • T1219.002 - Remote Desktop Software
  • T1204.001 - Malicious Link
  • T1587 - Develop Capabilities
  • T1036.004 - Masquerade Task or Service
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Contagious Interview

Score: 0.69
Matched TTPs:
  • T1587 - Develop Capabilities
  • T1219.002 - Remote Desktop Software
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Moonstone Sleet

Score: 0.67
Matched TTPs:
  • T1587 - Develop Capabilities
  • T1217 - Browser Information Discovery
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

APT29

Score: 0.62
Matched TTPs:
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
  • T1562.008 - Disable or Modify Cloud Logs
MITREへのリンク →

Magic Hound

Score: 0.60
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

APT28

Score: 0.58
Matched TTPs:
  • T1204.001 - Malicious Link
  • T1102.002 - Bidirectional Communication
  • T1498 - Network Denial of Service
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る