SCARLETEEL is a cloud-focused threat actor associated with campaigns against AWS and Kubernetes environments, including AWS Fargate workloads. The actor has used the AWS CLI as a living-off-the-land utility to retrieve tools from attacker-controlled S3-compatible storage and exfiltrate data from compromised cloud environments. SCARLETEEL has also been associated with misuse of Peirates, an open-source Kubernetes post-exploitation framework, to enumerate cloud and Kubernetes resources. Reported activity indicates an emphasis on post-compromise cloud discovery, tool transfer, and data theft through legitimate cloud administration tooling.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a threat group that misused Peirates for Kubernetes/cloud resource enumeration; described as part of earlier campaigns that targeted Kubernetes resources.
Referenced as an example associated with the use of compromised credentials for initial access.
Observed using the AWS CLI as a living-off-the-land technique in AWS environments to download tools and exfiltrate compromised data via an attacker-hosted S3-compatible backend.
Advanced attack campaign targeting cloud environments, especially AWS, for data theft and cryptojacking.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.