NetScan
NetScan is a well-known dual-use network reconnaissance and scanning tool used by threat actors during post-compromise discovery. In the provided reporting, attackers used NetScan to scan internal networks and support lateral movement and broader infrastructure compromise. One intrusion report specifically observed execution of netscan.exe from C:\ProgramData\VMware\lib2lib\netscan.exe during a ransomware attack that began with compromised SSL-VPN access, followed by credential theft, suspected DCSync activity, Microsoft 365 token abuse, cloud data exfiltration with rclone, and ransomware deployment. NetScan is also repeatedly cited as part of living-off-the-land or dual-use tooling sets alongside Netexec, MeshAgent, and modified Rustdesk in ransomware operations.
The content associates NetScan with multiple ransomware-related intrusions and operators. It was used in activity involving an anonymized ransomware intrusion investigated by Yarix, in campaigns involving the newly observed Osiris ransomware family targeting a major food service franchisee operator in Southeast Asia in November 2025, and in Storm-1175 activity linked by Microsoft to Medusa ransomware exploitation of Fortra GoAnywhere MFT CVE-2025-10035. In the Storm-1175 case, Microsoft explicitly described NetScan as being used for network reconnaissance after initial access. In the Osiris reporting, defenders were advised to monitor for NetScan as one of the tools used in the campaign.
High-confidence indicators directly mentioned in the content are limited. The content references a SHA256 entry for a NetScan sample but does not provide the full hash value in the supplied text. A concrete file path observed in one incident is C:\ProgramData\VMware\lib2lib\netscan.exe. Overall, NetScan should be understood here as a legitimate or dual-use reconnaissance utility frequently abused by ransomware operators and affiliates for internal network enumeration rather than as a bespoke malware family.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Techniques & procedures
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Discovery
4 techniques
Discovery
Sophos commonly observed Akira actors using built-in ping and net commands to discover additional systems in the environment and identify the status of target devices.
Sophos commonly observed Akira actors using built-in ping and net commands to discover additional systems in the environment... using tools such as Advanced IP Scanner and Netscan
IOCs tracked for this family
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Recent activity
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Netscan was used for internal network reconnaissance to identify reachable hosts and expand the attacker’s visibility across the environment.
Network scanning/reconnaissance tool referenced as used in the campaign to enumerate targets prior to ransomware deployment.
Dual-use network scanning tool used for discovery/reconnaissance during the intrusion preceding ransomware deployment.
Network reconnaissance/scanning utility used for discovery during post-exploitation prior to lateral movement and ransomware deployment.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.