Acunetix is identified in the provided content as a web vulnerability scanning tool observed on malicious infrastructure rather than as a traditional malware family. It was detected across multiple regional infrastructure analyses, including 38 unique C2 IPs in Middle Eastern hosting and telecom networks, and was also observed on Russian- and Chinese-hosted malicious infrastructure alongside tools such as Gophish and Interactsh. The reporting explicitly characterizes Acunetix as part of scanning and reconnaissance activity, indicating use for vulnerability discovery and support of follow-on intrusion or credential theft operations. Its presence on the same infrastructure as phishing kits, offensive frameworks, botnets, and espionage tooling suggests it is used by both criminal and state-linked operators as part of broader attack workflows. No specific infection vector, payload behavior, or standalone indicators of compromise for Acunetix itself are provided beyond its observed presence on malicious infrastructure and the count of 38 C2 IPs in the Middle East dataset.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Collecte d’informations sur l’hôte de la victime (T1592) – Collecte de détails techniques sur les serveurs web cibles, incluant Microsoft IIS 8.5, ASP.NET, PHP 5.3.1, et des composants spécifiques comme Telerik Web UI.
Scan Actif (T1595) – Scan de Blocs IP (T1595.001) : Réalisation de scans de masse sur des plages d’adresses IP en Israël, Jordanie, et d’autres pays pour identifier l’infrastructure. – Scan de Vulnérabilités (T1595.002) : Utilisation d’outils comme Nuclei et Acunetix pour sonder activement les actifs découverts à la recherche de vulnérabilités connues.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An offensive security scanning tool observed in malicious infrastructure across the region.
A scanning tool detected on the infrastructure, supporting reconnaissance activity.
Commercial vulnerability scanning tool observed in malicious infrastructure context (scanning/exploitation support).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.