Introduction
Scarred Manticore has been pursuing high-value targets for years, utilizing a variety of IIS-based backdoors to attack Windows servers. These include a variety of custom web shells, custom DLL backdoors, and driver-based implants.
Activities and Tactics
Country of Origin: 🇮🇷 Iran
First Seen: 2023
Last Activity: 2023
Notable Campaigns
Information pending cataloguing.
Tactics, Techniques, and Procedures (TTPs)
Information pending cataloguing.
Notable Indicators of Compromise (IOCs)
No atomic indicators are listed in this profile. The APTnotes snapshot indexes 1 public reports that may contain IOCs; see Source Attribution for dataset links.
Malware and Tools
- Backdoor.Oldrea
- Windows Remote Desktop
Attribution and Evidence
Country of Origin: Iran Additional attribution information pending cataloguing.
References
References pending cataloguing.