Uptime Hamster: 10d 12h 18mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Scarab

Scarab

0 incidentes 0 paises 0 sectores apt CN Ultimo: -
Aliases: Scieron, Trojan, HeaderTip, cosmicbeetle, scarab, spacecolon
Ver en IntelTracker → APTTrail →
Scarab is a ransomware group that first emerged in May 2017. Initially, the group gained prominence through extensive spam campaigns leveraging the Necurs botnet for distribution. Over time, Scarab evolved its tactics, shifting from broad, indiscriminate attacks to more targeted operations, exemplified by variants such as Scarabey that exploited Remote Desktop Protocol vulnerabilities and focused on specific geographical regions. More recently, Scarab ransomware has been associated with the CosmicBeetle group, which employs the Spacecolon toolkit for deploying its variants, with new builds observed as recently as May 2023. The group's primary motivation is financial gain through extortion. Scarab distinguishes itself by initially relying on mass spam distribution, using a flexible ransom note that does not specify a fixed amount, and introducing aggressive escalation tactics like threatening gradual file deletion if payment is delayed. While the threat actor shares its name with a Chin

Aliases del actor

ScieronTrojanHeaderTipcosmicbeetlescarabspacecolon

Actores similares

headertipactor · 1
Motivacion