NET_SCAN is a cybercrime-as-a-service platform associated with the XSS.is forum user xssNew and marketed through the related WordPress-focused service WP Magic Button. It operates as a criminal service ecosystem offering mass exploitation and monetization capabilities rather than a single malware family or intrusion set. Reported functionality includes WordPress mass credential checking and code injection, credential theft targeting cloud, hosting, and messaging services, sensitive data discovery, email spoofing, SMS fraud, bulk email operations, phishing-email generation, remote shell enablement, and cryptomining deployment. The operator has also used Telegram-based administration and promotion channels. The WP Magic Button component is focused on large-scale compromise of WordPress sites using multiple injection workflows, while the broader NET_SCAN platform supports harvesting and validation of credentials, scanning for exposed services and databases, and follow-on monetization. Exposed platform functionality has indicated theft and management of SMS-provider credentials, SMTP and email-service credentials, discovery of accessible databases, and deployment of a custom Monero-mining agent alongside XMRig with persistence on Linux systems. Observed tradecraft supports capabilities spanning initial access, credential theft, scanning and reconnaissance, persistence, defense evasion, post-exploitation, exfiltration of stolen credentials and service data, spoofing, and crypto-theft. The actor appears financially motivated, with services advertised commercially and designed to enable fraud, account abuse, infrastructure compromise, and illicit monetization. Known aliases and related branding include xssNew and WP Magic Button.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.