Advanced IP Scanner is a legitimate network scanning and host discovery utility that appears in multiple intrusion and ransomware investigations as a dual-use tool for internal reconnaissance and network mapping. In the cited incidents, attackers used it to identify other devices of interest on the same subnet, enumerate available network hosts, and support broader discovery activity. It was observed in operations associated with the Mad Liberator ransomware group, where it was used after access via abused AnyDesk sessions to identify potentially interesting devices on the victim subnet. It was also reported in activity involving the hacktivist/destructive group Twelve, alongside tools such as Cobalt Strike, Mimikatz, Chisel, BloodHound, PowerView, adPEAS, CrackMapExec, and PsExec, for credential theft, discovery, network mapping, and privilege escalation. Additional reporting noted attackers dropping a file masquerading as SoftPerfect Network Scanner that was actually Advanced IP Scanner, and listed it among tools seen in Akira ransomware campaign activity targeting SonicWall SSL VPN environments. The content does not provide unique malware-style persistence or payload behavior for Advanced IP Scanner itself; rather, it is consistently described as a legitimate scanner abused by threat actors for active scanning and host enumeration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The attacker then used Advanced IP Scanner to determine if there were other devices of interest that could be exploited within the same subnet.
Prominent among the other tools used by Twelve are Cobalt Strike, Mimikatz, Chisel, BloodHound, PowerView, adPEAS, CrackMapExec, Advanced IP Scanner, and PsExec for credential theft, discovery, network mapping, and privilege escalation.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Network scanning tools (AdFind, Advanced IP Scanner, SoftPerfect) map the environment.
In the same session the threat actor enumerated the domain over LDAP against the domain controller and queried the privileged groups and account information. They then tested access by attempting to authenticate to every host in the domain.
The attackers later deployed Slopoly and tools such as AzCopy and Advanced IP Scanner to expand access and move laterally within the network.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used for internal network enumeration/port scanning during the second phase of the intrusion to support lateral movement and targeting prior to ransomware deployment.
A network scanning tool abused by the attacker to identify other potentially interesting devices on the local subnet during the intrusion.
Legitimate network scanning utility used by the intruder for network service discovery during post-compromise discovery.
Network scanning tool used to discover hosts and services in victim environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.