Scarlet Goldfinch
Scarlet Goldfinch is a Red Canary-tracked threat/activity cluster described as a dropper that uses a distribution scheme similar to SocGholish. It uses JScript files to drop NetSupport Manager onto victim systems. Red Canary reported Scarlet Goldfinch as one of its prominent "color bird" threats in 2025, ranking second in April 2025, and also identified it as a dropper threat cluster in first-half 2025 reporting. The cluster has been observed delivered through paste-and-run social engineering activity, also referred to as ClickFix or fakeCAPTCHA, in which users are tricked into pasting and executing malicious commands. Supporting reporting also notes broader delivery methods used across Red Canary-tracked prevalent threats in 2025, including fake browser updates, malvertising, SEO poisoning, compromised browser extensions, and potentially unwanted programs, but the high-confidence behavior directly attributed to Scarlet Goldfinch is the use of JScript to deploy NetSupport Manager. NetSupport Manager is a legitimate remote access tool that adversaries abuse for unauthorized remote control. No specific industries, geographies, or standalone IOCs were provided for Scarlet Goldfinch in the supplied content.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Execution
3 techniques
Execution
In most scenarios, once users interact with the Fix or Verify button in the lure, the button will covertly copy an obfuscated PowerShell command to the clipboard and present the user with “verification steps.”
Collection
1 technique
Collection
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named threat/tool delivered via paste-and-run campaigns.
Activity cluster using JScript files to drop NetSupport Manager, similar to SocGholish distribution schemes.
A Red Canary-named color bird threat described as a dropper.
A Red Canary-tracked activity cluster that uses JScript-based delivery and a SocGholish-like distribution scheme to deploy NetSupport Manager.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.