Advanced Port Scanner is a port-scanning and network discovery tool observed in post-compromise activity. In the provided reporting, it was executed as advanced_port_scanner.exe by Iranian state-sponsored actors identifying as HomeLand Justice during the 2022 intrusions against the Government of Albania, where it was used after initial access obtained via exploitation of Microsoft SharePoint CVE-2019-0604 and alongside persistence through ASPX webshells, lateral movement via RDP/SMB/FTP, Exchange compromise, credential harvesting, and destructive follow-on activity including ransomware-style encryption and deployment of a ZeroCleare variant. Separate reporting also lists Advanced Port Scanner among tools used in a coordinated Akira ransomware campaign targeting SonicWall SSL VPN appliances in 2025; that campaign involved initial access via SonicWall SSL VPN, discovery, lateral movement, staging with WinRAR and rclone, attempted exfiltration via SCP and Cloudflare R2, ransomware deployment, and deletion of VSS copies. High-confidence identifiers from the content include the executable name advanced_port_scanner.exe and the alias Advanced Port Scanner.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
T1027. Obfuscated Files or Information Trigona operators use UPX to pack DC2.exe and DC4.exe to avoid static signature detection. For DC6.exe , Trigona hid the installer for Advanced Port Scanner within Inno Setup installer to evade static signature detection.
les outils de reconnaissance réseau Advanced Port Scanner et Advanced IP Scanner de FAMATECH ont été découverts sur le système d’information [T1016].
LockBit affiliates map the environment before moving further, using Netscan and Advanced Port Scanner to scan the internal network for live hosts, open ports and potential targets.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.