Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareRansomwareUsed by 1 actor

NetScan

NetScan is a well-known dual-use network reconnaissance and scanning tool used by threat actors during post-compromise discovery. In the provided reporting, attackers used NetScan to scan internal networks and support lateral movement and broader infrastructure compromise. One intrusion report specifically observed execution of netscan.exe from C:\ProgramData\VMware\lib2lib\netscan.exe during a ransomware attack that began with compromised SSL-VPN access, followed by credential theft, suspected DCSync activity, Microsoft 365 token abuse, cloud data exfiltration with rclone, and ransomware deployment. NetScan is also repeatedly cited as part of living-off-the-land or dual-use tooling sets alongside Netexec, MeshAgent, and modified Rustdesk in ransomware operations.

The content associates NetScan with multiple ransomware-related intrusions and operators. It was used in activity involving an anonymized ransomware intrusion investigated by Yarix, in campaigns involving the newly observed Osiris ransomware family targeting a major food service franchisee operator in Southeast Asia in November 2025, and in Storm-1175 activity linked by Microsoft to Medusa ransomware exploitation of Fortra GoAnywhere MFT CVE-2025-10035. In the Storm-1175 case, Microsoft explicitly described NetScan as being used for network reconnaissance after initial access. In the Osiris reporting, defenders were advised to monitor for NetScan as one of the tools used in the campaign.

High-confidence indicators directly mentioned in the content are limited. The content references a SHA256 entry for a NetScan sample but does not provide the full hash value in the supplied text. A concrete file path observed in one incident is C:\ProgramData\VMware\lib2lib\netscan.exe. Overall, NetScan should be understood here as a legitimate or dual-use reconnaissance utility frequently abused by ransomware operators and affiliates for internal network enumeration rather than as a bespoke malware family.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Storm-1175

"...utilized Netscan for network reconnaissance..."

via bleeping computerbleepingcomputer.com
MITRE ATT&CK

Techniques & procedures

5 distinct techniques documented for this family, organized by ATT&CK tactic.

Discovery

4 techniques
T1016System Network Configuration DiscoveryEvidence5

Sophos commonly observed Akira actors using built-in ping and net commands to discover additional systems in the environment and identify the status of target devices.

T1018Remote System DiscoveryEvidence1

Sophos commonly observed Akira actors using built-in ping and net commands to discover additional systems in the environment... using tools such as Advanced IP Scanner and Netscan

T1046Network Service DiscoveryEvidence11

Other than built-in commands, there were also cases where they have used tools like Angry IP scanner, Advanced IP scanner and netscan.

T1482Domain Trust DiscoveryEvidence1

the other internal network discovery via tools such as Advanced IP Scanner and Netscan to obtain Active Directory information.

Command and Control

1 technique
T1105Ingress Tool TransferEvidence1

"INC Ransom affiliates transfer various tools into the target environments... such as NetScan, 7-Zip and FileZilla"

INDICATORS OF COMPROMISE

IOCs tracked for this family

1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
1 tracked

IPs, domains, and DNS infrastructure linked to this family.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app4 months ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching1

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping5

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.