Netskope Threat Labs

Crimson

ATP Sandbox Adv. Heuristics

Crimson is a remote access trojan associated with state sponsored actors that has targeted government and military organizations in South Asia. Written in C sharp and delivered through spear phishing documents, it connects to its operators on schedule, collects files and credentials, and uploads stolen data. Persistent operation balances the family's modest feature set, and new variants continue to surface in long running regional campaigns.

First seen
May 2022
Last seen
September 2026

30 techniques across 10 tactics.

TA0002 Execution

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

TA0006 Credential Access

  • T1555Credentials from Password Stores

TA0007 Discovery

  • T1012Query Registry
  • T1016System Network Configuration Discovery
  • T1033System Owner/User Discovery
  • T1057Process Discovery
  • T1082System Information Discovery
  • T1083File and Directory Discovery
  • T1120Peripheral Device Discovery
  • T1124System Time Discovery
  • T1518Software Discovery
  • T1614System Location Discovery
  • T1680Local Storage Discovery

TA0008 Lateral Movement

  • T1091Replication Through Removable Media

TA0009 Collection

TA0011 Command and Control

TA0010 Exfiltration

  • T1041Exfiltration Over C2 Channel

TA0112 Defense Impairment

Alert Name
ByteCode-MSIL.Trojan.Crimson
Shortcut.Trojan.Crimson
Win32.Ransomware.Crimson
Win32.Spyware.Crimson
Win32.Trojan.Crimson