masscan is a high-speed network scanning tool used to identify exposed services across large IP ranges. In the provided reporting, it is repeatedly used by threat actors for reconnaissance and worm-like propagation rather than as a standalone malicious payload. Observed uses include scanning actor-supplied IP ranges for exposed Docker daemons on ports 2375 and 2376, often paired with zgrab to validate responses such as /v1.16/version before reporting vulnerable targets back to command-and-control infrastructure. It is also described being used to scan for internet-exposed RDP services on port 3389 and internal/private network ranges for SSH services on port 22. The content links its use to multiple campaigns, including a June 2023 cloud credential theft operation with overlaps to TeamTNT tradecraft targeting exposed Docker services in AWS, Azure, and GCP environments; a TOR-enabled cryptojacking campaign targeting misconfigured Docker APIs and propagating via port 2375 scanning; PARINACOTA human-operated ransomware activity using Masscan.exe for RDP target discovery; and 8220 gang activity using masscan for SSH reconnaissance and lateral movement in containerized/cloud environments. Mentioned artifacts include Masscan.exe and masscan_1.3.0.exe. The content does not describe masscan itself as malware, but as a legitimate scanner abused by threat actors for reconnaissance, target discovery, and propagation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Разведка сигнальной инфраструктуры - Gather Victim Network Information (T1590, Reconnaissance). Сбор point codes, Global Titles, Diameter realms, GTP-эндпоинтов из публичных IR.21-документов, DNS-записей GRX/IPX.
The researchers scanned the internet for 22 paths that could contain Swagger specifications, using passive HTTP/HTTPS data combined with an internet-wide masscan to fill gaps.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Masscan is a network scanner used by attackers to scan for open ports, in this case to find exposed Docker APIs and propagate the infection.
High-speed port scanner included among tools in Evidencia.rar; likely used for internal/external scanning and target discovery.
A high-speed network scanner used by the embedded propagation script to scan large IP ranges for exposed Docker services on ports 2375 and 2376.
Network scanner used to identify hosts with open SSH ports for subsequent brute-force and exploitation attempts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.