Scarlet Goldfinch is an activity cluster and initial-access threat first observed in mid-2023 that uses compromised websites and social-engineering lures to trick users into executing malicious code. It is widely associated with fake browser update lures similar to SocGholish and later evolved to heavily use malicious copy-and-paste, also known as paste-and-run or FakeCAPTCHA, as an execution mechanism. Other researchers have tracked related activity under the names SmartApeSG and ZPHP. The cluster’s primary objective has been delivery of NetSupport Manager, a legitimate remote monitoring and management tool abused for unauthorized remote access and persistence. Scarlet Goldfinch has also been observed delivering additional payloads including LummaC2, and later-stage chains have included Remcos, with some reporting also linking follow-on activity to StealC and ArechClient2. Scarlet Goldfinch remained operationally consistent while repeatedly changing its delivery and execution chains, especially throughout 2025 and into early 2026. Early Scarlet Goldfinch activity relied on users downloading and executing JScript from archives presented as browser updates on compromised websites. Those chains commonly executed through wscript.exe and progressed through batch, VBS, or obfuscated PowerShell stages to install NetSupport Manager. Persistence has been established through Registry Run keys, scheduled tasks, Startup-folder shortcuts, and logon-script style mechanisms. In 2025 the cluster shifted from fake-update JavaScript lures to paste-and-run chains that instructed victims to execute malicious commands manually. Across multiple epochs, Scarlet Goldfinch rotated among native Windows utilities and LOLBAS-style tooling including cmd.exe, curl.exe, PowerShell, msiexec.exe, mshta.exe, finger, forfiles, tar, wscript.exe, and WMI-based process creation. It also used command obfuscation, delayed environment variable expansion, nested shell execution, and DLL sideloading to reduce detection overlap and complicate analysis. A defining characteristic of Scarlet Goldfinch is rapid tradecraft iteration without changing its core mission: initial access leading to remote-control payload deployment. Throughout 2025, the cluster repeatedly altered command syntax, downloader choice, persistence method, and execution flow while maintaining continuity through shared infrastructure, server-side web injects, and recurring payload patterns. This combination of compromised-site lures, user-execution tradecraft, abuse of legitimate administration software, and frequent defense-evasion changes makes Scarlet Goldfinch a prevalent and adaptable intrusion cluster.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
28 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Activity cluster using compromised websites to socially engineer users into executing malicious code.
Activity cluster using compromised websites to trick users into executing malicious code, associated in the article with ClickFix-style activity.
Uses compromised websites and fake browser update or paste-and-run lures to trick users into executing malicious code, leading to payload delivery including NetSupport Manager and Remcos.
A Red Canary-named threat cluster whose tradecraft was significantly updated in 2025 and which ranked as the number 6 threat in the report.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.