Netskope Threat Labs

ScareCrow

ATP Sandbox Adv. HeuristicsAV

ScareCrow is a JavaScript based dropper that delivers additional malware payloads through obfuscated code designed to frustrate analysis. Its scripts arrive through phishing and compromised websites, and successful execution downloads follow on payloads such as stealers and remote access trojans. Detections under this name indicate that a script executed and attempted further downloads, so responders should hunt for the payloads it fetched.

First seen
April 2022
Last seen
September 2026
Alert Name
Gen:Trojan.ScareCrow.Gen.1
GT:JS.ScareCrow.3.D2ADB71C
GT:JS.ScareCrow.6.08B21C41
GT:JS.ScareCrow.6.0F265489
GT:JS.ScareCrow.6.1753B918
GT:JS.ScareCrow.6.2894AA22
GT:JS.ScareCrow.6.2DC57452
GT:JS.ScareCrow.6.508BBBEC
GT:JS.ScareCrow.6.56BBA184
GT:JS.ScareCrow.6.57AEC965