A security alert regarding APT-C-28 (ScarCruft) using MiradorShell to launch a cyberattack.
Essential information
- Published
- 09/02/2026 10:18
- Modified
- 09/02/2026 11:44
- Tags
- 2026-02-09 backdoor miradorshell phishing scarcruft
- Related entities
- 4 observables, 1 intrusion sets (apt), 16 techniques (mitre), 1 malware, 2 others
Description
A recent investigation reveals that the APT-C-28 (ScarCruft) group has expanded its targets to include the cryptocurrency industry. The group employs sophisticated phishing tactics, using LNK files disguised as PDFs to lure victims with investment proposals ranging from $1-3 million. Upon execution, a multi-stage payload deployment occurs, ultimately installing MiradorShell v2.0 to gain system control. The attack chain involves file downloads, decryption, and the creation of scheduled tasks for persistence. MiradorShell, an AutoIt-based backdoor, connects to a command and control server, offering reverse shell capabilities, file management, remote program execution, and victim fingerprinting. The malware employs various evasion techniques, including inline library files and direct API calls.