SCARLETEEL

Primary motivation
financial-gain
Sophistication
advanced
Resource level
team
Actor type
criminal
Profile updated
2026-07-07 12:08:12

Targeted industries: technology-and-telecommunications financial-services government-and-public-sector healthcare-and-pharmaceutical

Context

SCARLETEEL is a threat actor that primarily targets cloud environments, specifically AWS and Kubernetes. They have been observed stealing proprietary data and intellectual property, as well as conducting cryptomining operations. SCARLETEEL employs sophisticated tactics and tools to bypass security measures and gain unauthorized access to accounts, often exploiting vulnerabilities in containerized workloads and misconfigurations in AWS policies.

Reports & references

  • sysdig.com — Scarleteel 2 0 (report)
  • sysdig.com — Cloud Breach Terraform Data Theft (report)

External references