Description
Crimson is a remote access trojan associated with state sponsored actors that has targeted government and military organizations in South Asia. Written in C sharp and delivered through spear phishing documents, it connects to its operators on schedule, collects files and credentials, and uploads stolen data. Persistent operation balances the family's modest feature set, and new variants continue to surface in long running regional campaigns.
Stats
- First seen
- May 2022
- Last seen
- September 2026
MITRE ATT&CK techniques
30 techniques across 10 tactics.
TA0005 Stealth
TA0007 Discovery
- T1012Query Registry
- T1016System Network Configuration Discovery
- T1033System Owner/User Discovery
- T1057Process Discovery
- T1082System Information Discovery
- T1083File and Directory Discovery
- T1120Peripheral Device Discovery
- T1124System Time Discovery
- T1518Software Discovery
- T1518.001Security Software Discovery
- T1614System Location Discovery
- T1680Local Storage Discovery
TA0008 Lateral Movement
- T1091Replication Through Removable Media
TA0009 Collection
TA0011 Command and Control
TA0010 Exfiltration
- T1041Exfiltration Over C2 Channel
TA0112 Defense Impairment
- T1112Modify Registry
Associated groups
Associated campaigns
Alert name variants
| Alert Name |
|---|
| ByteCode-MSIL.Trojan.Crimson |
| Shortcut.Trojan.Crimson |
| Win32.Ransomware.Crimson |
| Win32.Spyware.Crimson |
| Win32.Trojan.Crimson |