Scarred Manticore is an Iranian state-linked cyber-espionage actor associated with OilRig/APT34 activity. It primarily targets high-profile government and telecommunications organizations in the Middle East, including Israeli municipal targets. The actor is assessed to specialize in establishing initial footholds and conducting long-term intelligence collection, at times providing access later used by Void Manticore for disruptive or destructive operations. Scarred Manticore has exploited internet-facing Microsoft SharePoint servers, including CVE-2019-0604, and has used the LIONTAIL framework on compromised Windows servers. LIONTAIL employs customized, memory-resident shellcode loaders and passive implants that abuse undocumented Windows HTTP.sys functionality to receive and decode selected inbound HTTP traffic. Per-host customized implants, reverse proxies, reverse shells, obfuscation, masquerading, and web-protocol communications support stealthy collection and exfiltration while blending malicious traffic with normal network activity. Observed activity also includes persistence through server software components and boot or logon autostart mechanisms, system discovery, remote-services-based movement, and collection of email and data from information repositories.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
18 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as collaborating with MOIS-linked persona operations within the same broader ecosystem.
Associated with the LionTail framework; creates unique implants per compromised host and exfiltrates data while disguising C2 traffic as normal network traffic.
Associated with LionTail framework activity, generating unique implants per host and conducting stealthy data exfiltration while masking C2 within normal-looking HTTP traffic.
Referenced as the prior access-side actor in an earlier handoff model to Void Manticore/Handala.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.