NBTScan is a NetBIOS network-scanning utility used to enumerate systems across IP ranges and retrieve NetBIOS name information. It can identify remote accessible hosts, list NetBIOS computer names and active users, and print captured packet content. Threat actors have used NBTScan for internal network reconnaissance, host discovery, network-service discovery, and environment mapping following compromise. Documented users include BISMUTH, Earth Kurma, Earth Krahang, Agrius, TA428, FamousSparrow, APT39, Mustang Panda, Operation Wocao, and Sofacy. It has been used in Windows enterprise environments, including alongside credential theft and lateral-movement activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
An IOC is detected as “Win32/NetTool.Nbtscan.A” and described as “Nbtscan.”
"the co-opted Word 2007 process dropped and loaded a scanning tool popular among attackers, NbtScan.exe. BISMUTH then immediately used the scanning tool to scan an IP address range within the organization."
Agrius used the tool NBTscan to scan for remote, accessible hosts in victim environments.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Sandworm Team used BlackEnergy’s network sniffer module to discover user credentials being sent over the network...; APT33 has used SniffPass to collect credentials by sniffing network traffic; ArcaneDoor included network packet capture and sniffing...; multiple tools (CASTLETAP, Impacket, Empire, PoshC2, etc.) described as sniffing/packet capture.
The ATT&CK mapping notes use of a modified nbtscan; the group scanned internal address ranges and identified devices with open ports.
Several actors used discovery tools such as BloodHound, AdFind, Advanced IP Scanner, SoftPerfect Network Scanner, NBTscan, RustScan, and SNScan for user, system, and network discovery.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Sandworm Team used BlackEnergy’s network sniffer module to discover user credentials being sent over the network...; APT33 has used SniffPass to collect credentials by sniffing network traffic; ArcaneDoor included network packet capture and sniffing...; multiple tools (CASTLETAP, Impacket, Empire, PoshC2, etc.) described as sniffing/packet capture.
The ‘n.exe’ file that was downloaded and executed by Poison Ivy is a public NBTScan tool. When the tool is executed, it is possible to scan for hosts on the target network.
The infected system had a scanning tool, proxy and port forwarding tool, WebShell, backdoor malware, etc. The attacker used various tools for different purposes: collecting information for infiltration...
Examples include 'Caterpillar WebShell can obtain a list of user accounts from a victim's machine,' 'DRATzarus can obtain a list of users from an infected machine,' 'Woody RAT can retrieve a list of user accounts and usernames from an infected machine,' and 'TrickBot can identify the user and groups the user belongs to on a compromised host.'
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
NBTScan is a network scanner used to enumerate NetBIOS name information across IP networks for reconnaissance purposes.
Tool/malware component that can list active users on the system.
Lists active users on the system.
NetBIOS scanning utility used for discovery of hosts/services in the victim environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.