Dark Scorpius is a financially motivated cybercriminal threat actor associated with large-scale social-engineering intrusions. The group has been reported to have compromised more than 500 victims since 2022. Its operations prominently involve impersonating IT staff to deceive targets and obtain remote access, with some compromises reportedly achieved in as little as 14 hours. Dark Scorpius has been identified as a notable attacker in the context of Olympics-related cyber risk, where phishing, business email compromise-style deception, credential harvesting, and abuse of trusted identities and business processes are assessed as key intrusion patterns. Available reporting supports Dark Scorpius as a criminal actor focused on initial access through spoofing and follow-on remote compromise rather than as a state-sponsored espionage group. No high-confidence attribution to a specific country is currently available from the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Identified as a notable attacker in the context of Olympics-targeted intrusions; specific operation type (ransomware/espionage/hacktivism) is not attributed in the provided content.
Impersonates IT staff to socially engineer victims and obtain remote access rapidly; cited as an example threat actor likely to target large sporting events via phishing/spoofing-driven initial access.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.