xssNew
xssNew is a cybercrime actor identified as the operator of NET_SCAN, a fully operational cybercrime-as-a-service (CaaS) platform. The actor is described in the source content as an XSS.is forum Premium member since July 2022 and used the Telegram handle @NET_SCAN_Admin, with additional bots @NET_SCAN_bot and @netscan_bot. The content links xssNew to both netscan[.]info and the WordPress-focused spinoff wpmagic[.]net through shared infrastructure and source-code artifacts. According to the provided reporting, NET_SCAN offered modules and services for WordPress exploitation, bulk WordPress credential checking, code injection, remote shell access, AWS, cPanel, and SSH credential theft, sensitive file scanning, database operations, email spoofing, SMS fraud, bulk email campaigns, AI phishing email generation, Telegram and WhatsApp automation, Telerik exploit DLL generation, text-to-speech, and cryptomining. The WP Magic Button component supported four WordPress injection methods: Theme Editor, File Manager, Plugin Editor, and Plugin Loading, and classified outcomes as Good, Injected, NoPlugin, or Bad Clone Missed. The content states that unauthenticated API endpoints on netscan[.]info exposed stolen SMS and SMTP credentials, provider statistics, discovered databases, scanner logs, and a full miner installation script. The cryptomining capability used a custom Go binary named multimmm-user, bundled XMRig for Monero mining, persisted via a systemd service named multimmm-user.service, and communicated with a WebSocket C2 at wss://netscan[.]info/api/miners/ws/agent. The reporting also notes that xssNew advertised "Magic Button - Project from the Net Scan" on XSS.is with multiple pricing tiers. The actor is associated in the content only with cybercrime activity; no nation-state attribution is stated. Known alias in the provided content: xssnew.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Health Care Equipment & Services
- Government & Administration
- Financial Services
- Consumer Services
- Academia & Research
Where they target
Geographies tied to known operations.
- 🇬🇧 United Kingdom
- 🇵🇰 Pakistan
- 🇵🇭 Philippines
Where they're from
Attributed origin per open-source reporting.
- RU
Tradecraft
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Observables
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.