xssNew is a cybercrime actor associated with operation of the NET_SCAN cybercrime-as-a-service platform and the related WordPress-focused service WP Magic Button. The actor has been identified as a user of the XSS.is criminal forum and has advertised services for mass WordPress credential checking and code injection, credential theft, SMS fraud, email spoofing, remote shell access, sensitive-data scanning, database discovery, bulk email operations, and cryptomining deployment. The infrastructure and source-code relationships between NET_SCAN and WP Magic Button indicate common operation and a service ecosystem oriented toward monetized criminal abuse rather than espionage. The actor’s tooling supports multiple stages of the intrusion lifecycle. Observed capabilities include initial access through WordPress exploitation and credential abuse; credential theft targeting cloud, hosting, SSH, SMTP, and messaging-service accounts; post-compromise remote shell access; scanning for sensitive files and exposed databases; and deployment of Monero mining infrastructure on compromised Linux systems. The mining component used a custom agent together with XMRig and established persistence through a system service, demonstrating operational support for persistence and post-exploitation. The platform also exposed functionality for email spoofing, phishing-email generation, Telegram and WhatsApp automation, and exploit-related tooling, indicating a broad criminal service portfolio. Known branding and aliases directly tied to the operation include NET_SCAN, WP Magic Button, and xssNew. The actor has also used Telegram identities associated with NET_SCAN administration and bot operations. Reported victim exposure included organizations whose stolen SMS and mail-service credentials were present in the platform, and the WordPress-focused component was designed for bulk compromise and code injection across websites. The overall activity profile is consistent with a financially motivated cybercrime operator providing offensive services and monetization mechanisms including credential theft and illicit cryptomining.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.