HeaderTip
- First seen
- 2023-02-01 00:00:00
- Malware type
- backdoor
- Profile updated
- 2026-07-07 13:00:47
Targeted industries: government-and-public-sector
Targeted regions: country_code:cn
Context
The Chinese threat actor "Scarab" is using a custom backdoor dubbed "HeaderTip" according to SentinelLABS. This malware may be the successor of "Scieron".
Detection coverage
- 3 YARA rules
Detection rules
- MALPEDIA_Win_Headertip_Auto (yara-rule)
- BLACKBERRY_Headertip (yara-rule)
- SEKOIA_Backdoor_Win_Headertip (yara-rule)
Reports & references
- sentinelone.com — Chinese Threat Actor Scarab Targeting Ukraine (report)
- cip.gov.ua — Khto Stoyit Za Kiberatakami Na Ukrayinsku Kritichnu Informaciinu Infrastrukturu Statistika 15 22 Bereznya (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Headertip (report)
- blogs.blackberry.com — Threat Thursday Headertip Backdoor Shows Attackers From China Preying On Ukraine (report)
- CERT-UA — 38097 (report)
- esentire.com — Esentire Threat Intelligence Malware Analysis Headertip (report)