Scarlet Goldfinch is an activity cluster and initial-access threat active since at least June 2023 that uses compromised websites and social-engineering lures to trick users into executing malicious code. It is most closely associated with fake browser update campaigns resembling SocGholish-style operations and, beginning in 2025, with large-scale “paste-and-run” or fake CAPTCHA lures that coerce users into copying and executing malicious commands. Scarlet Goldfinch is tracked as distinct from SocGholish because, despite similarities in initial lure themes and JavaScript-based delivery, its downstream intrusion patterns and payloading differ. Other researchers have associated overlapping activity with the names SmartApeSG and ZPHP. The cluster primarily delivers NetSupport Manager, a legitimate remote monitoring and management tool abused for unauthorized remote access and persistence. NetSupport Manager has remained Scarlet Goldfinch’s core payload across multiple operational phases, although additional payloads have been observed, including LummaC2 as a tertiary payload and, in later 2025 activity, Remcos as an intermediate or alternate remote-access component. Follow-on reporting has also linked some Scarlet Goldfinch activity to StealC and ArechClient2. Early Scarlet Goldfinch activity relied on users downloading and executing malicious JScript, often delivered in archive files and launched via the Windows script host. Initial stages downloaded additional components that installed NetSupport Manager and established persistence through scheduled tasks and Windows Registry Run-key mechanisms. Around October 2023, the cluster shifted portions of its second-stage execution from batch and VBS scripting toward obfuscated PowerShell. In 2025, Scarlet Goldfinch significantly evolved its tradecraft and became strongly associated with malicious copy-and-paste execution. From April 2025 onward, it moved from fake browser update lures to fake CAPTCHA and related paste-and-run workflows while preserving the same objective of deploying remote-access tooling. Across multiple distinct operational epochs in 2025 and early 2026, the cluster repeatedly changed its command execution chains, downloader syntax, and persistence methods to reduce behavioral overlap and complicate detection. Observed execution chains variously used native Windows utilities and LOLBAS components including cmd, PowerShell, curl, msiexec, mshta, finger, forfiles, WMI-based process creation, and archive extraction utilities. The actor also experimented with nested shell execution, delayed environment variable expansion, caret-based obfuscation, and splitting download from execution to evade detections focused on specific binaries making network connections. Despite these frequent changes, Scarlet Goldfinch’s operations show continuity through shared infrastructure patterns, recurring server-side web injects, and repeated later-stage payload behavior. In several 2025 phases, the cluster staged archives masquerading as benign files, extracted them locally, and launched payloads through renamed binaries or DLL sideloading. In late 2025 and early 2026, Remcos appeared in some chains, sometimes preceding eventual NetSupport Manager deployment, suggesting experimentation with tooling while maintaining the broader access objective. Scarlet Goldfinch is not publicly established as a nation-state actor. Available reporting supports characterization as a financially motivated or criminally aligned intrusion cluster focused on scalable initial access and remote-control enablement rather than espionage. Its targeting is opportunistic and broad, leveraging compromised websites and user-execution lures that can affect many organizations. Because it abuses legitimate administration software and blends malicious activity into common browser-update and verification workflows, Scarlet Goldfinch poses a persistent detection challenge in enterprise environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
28 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Activity cluster using compromised websites to trick users into executing malicious code, associated in the article with ClickFix-style activity.
Uses compromised websites and fake browser update or paste-and-run lures to trick users into executing malicious code, leading to payload delivery including NetSupport Manager and Remcos.
A Red Canary-named threat cluster whose tradecraft was significantly updated in 2025 and which ranked as the number 6 threat in the report.
Uses malicious scripts executed from archive files as an initial access technique, with script execution followed by network activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.