CSIDB logo
Threat actor

ScarletMimic

Attribution profile

Type
Nation State
Location
China
Known incidents
0 incidents
First seen
-
Last seen
-
Updated
2026-07-31 01:24
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

ScarletMimic is a threat actor tracked under that alias and is known to operate from China according to available context. Public reporting links the actor to North Korean state‑linked activity, citing similarities in malware and infrastructure observed during investigations. The actor’s activities have been attributed to a state nexus rather than a criminal consortium based on government statements and technical evidence.

The actor’s targeting has focused on the nuclear energy sector in South Korea, as demonstrated by an intrusion against Korea Hydro and Nuclear Power. Strategic objectives observed in that operation included financial gain through extortion demands, disruption via threats to shut down reactors, and espionage aimed at stealing technical and personal data for potential sale. These objectives were explicitly stated in the attacker’s communications and the victim’s impact assessments.

Notable tactics, techniques and procedures employed by ScarletMimic include large‑scale phishing campaigns as the initial access vector, with 5,986 phishing messages sent to 3,571 employees in the reported case. The malware used in the intrusion shared composition and working methods with the kimsuky family associated with North Korean hackers, and the malicious code was compiled on a system configured for the Korean language. These elements illustrate a consistent pattern of socially engineered delivery followed by custom malware deployment.

A representative operation attributed to ScarletMimic is the 2015 compromise of Korea Hydro and Nuclear Power, during which personal information of 10,799 employees was exfiltrated, partial reactor blueprints were leaked via Twitter, and the attackers demanded monetary payment while threatening to disable three nuclear plants and sell sensitive data. This campaign exemplifies the actor’s blend of financially motivated extortion, disruptive threats, and espionage‑oriented data theft within a single incident.

Incidents

Attributed incidents are available to members.

0 incidents
CSIDB