Scarab is a Windows ransomware family active since at least 2017 and associated with both commodity malspam distribution and manually operated enterprise intrusions. It encrypts victim files and appends Scarab-family extensions, then presents ransom instructions demanding payment for decryption. Reported Scarab variants and descendants include Scarabey and later builds using multiple alternate extensions, reflecting ongoing repackaging and rebranding within the family.
Scarab has been distributed through large-scale spam operations, including campaigns delivered via the Necurs botnet using archive attachments that contained script-based downloaders. It has also been observed in broader criminal ecosystems linked to TA505, which has at times used Scarab alongside other ransomware families. In addition to email-borne delivery, Scarab-family activity has been associated with attacks exploiting weak or exposed remote access services, especially RDP, enabling operators to deploy ransomware manually after gaining access.
Behavior attributed to Scarab-family variants includes file encryption using strong symmetric cryptography, ransom-note creation, and anti-recovery actions intended to hinder restoration. Documented variants have deleted shadow copies and disabled Windows recovery-related features, and some Scarabey builds added destructive pressure by threatening or performing staged file deletion if victims did not engage quickly. In targeted ransomware tradecraft, Scarab has also appeared in intrusion chains involving credential theft, privilege escalation, lateral movement, network discovery, and domain-wide deployment using administrative tools and scripts before encryption.
Scarab primarily targets Windows systems and has affected organizations across multiple sectors and geographies. The family has appeared in both opportunistic campaigns and more selective ransomware operations, making it part of the broader evolution from mass-distributed ransomware toward hands-on-keyboard enterprise compromise and extortion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TA505 aurait pratiqué un usage ponctuel d’autres rançongiciels (Bart, Jaff, Scarab, Philadelphia, GlobeImposter et GandCrab).
7 distinct techniques documented for this family, organized by ATT&CK tactic.
42 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Parent ransomware family from which Scarabey is described as a variant/descendant.
Ransomware delivered via Necurs botnet malspam. It is downloaded by VBS attachments, encrypts files with the .scarab extension, and displays ransom/decryption instructions, including persistence via a registry key to show the ransom note on reboot.
researchers at SentinelOne have tied the malware campaign to the suspected Chinese group of threat actors known as Scarab. The Scarab malware was first observed in 2012 targeting organizations in Russia, Ukraine, United States, Chile, and Syria.
Named as another ransomware family that Dr. Shifro claimed it could decrypt.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.