Scarab

MISP
Type:
Nation-state
Country:
CN
First seen:
Unknown
Details:

Scarab APT was first spotted in 2015, but is believed to have been active since at least 2012, conducting surgical attacks against a small number of individuals across the world, including Russia and the United States. The backdoor deployed by Scarab in their campaigns is most commonly known as Scieron.

Metadata
ID: 353
Created: 13/01/2026 17:48
Updated: 08/03/2026 04:00