NetScan is a dual-use network reconnaissance utility used by threat actors during post-compromise operations to enumerate hosts and map victim environments. It has been observed in ransomware intrusions as part of hands-on-keyboard activity intended to identify additional systems for lateral movement and broader impact. Reported use includes campaigns associated with Play ransomware activity, Medusa affiliate operations tracked as Storm-1175, and an intrusion involving Osiris-related tooling, where it appeared alongside other administrative or remote-management tools such as NetExec and MeshAgent.
The tool’s observed role is reconnaissance rather than payload delivery or encryption. Operators use it after gaining access to a network to scan internal infrastructure and support expansion of the compromise. Because it is a legitimate or dual-use utility rather than malware purpose-built solely for malicious activity, attribution should focus on the surrounding intrusion set rather than the tool alone. High-confidence reporting supports its use on Windows systems in enterprise environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Extensive reconnaissance was conducted to map the network infrastructure.
Storm-2570 routinely conducts internal network discovery using tools such as NetScan, SoftPerfect Network Scanner Portable, and Nmap.
T1069. Permission Groups Discovery Trigona operators use NetScan to enumerate the security-enabled local group membership of the Administrators group.
Unit 42 researchers observed Royal threat actors using the network discovery software NetScan to identify and map out various connected computer resources such as other user targets and shares.
Files Delete[.]me – File observed during reconnaissance activity, commonly associated with NetScan
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Netscan was used for internal network reconnaissance to identify reachable hosts and expand the attacker’s visibility across the environment.
Network scanning/reconnaissance tool referenced as used in the campaign to enumerate targets prior to ransomware deployment.
Dual-use network scanning tool used for discovery/reconnaissance during the intrusion preceding ransomware deployment.
Network reconnaissance/scanning utility used for discovery during post-exploitation prior to lateral movement and ransomware deployment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.