SoftPerfect Network Scanner is a legitimate commercial network-discovery and host-profiling utility, not malware. It performs subnet and host enumeration and can identify network services and shared folders. It has been repeatedly used by financially motivated ransomware operators and other intrusion sets for internal reconnaissance, target-list construction, and Active Directory environment mapping after gaining access to Windows enterprise networks. Observed use includes activity associated with BlackCat/ALPHV affiliates, Everest ransomware activity, Akira affiliates, Crypt Ghouls, and multiple clusters exploiting NetScaler appliances. The tool’s presence alone is not evidence of malicious activity; its security relevance depends on execution context, operator authorization, and associated post-compromise behavior.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The file was identified as a version of the SoftPerfect Network Scanner – a powerful commercial network-scanning tool with the ability to discover shared folders and available services.
"...utilities, including SoftPerfect Network Scanner, PingCastle, and XenAllPasswordPro..."
"...utilities, including SoftPerfect Network Scanner, PingCastle, and XenAllPasswordPro..."
"...utilities, including SoftPerfect Network Scanner, PingCastle, and XenAllPasswordPro..."
"...utilities, including SoftPerfect Network Scanner, PingCastle, and XenAllPasswordPro..."
10 distinct techniques documented for this family, organized by ATT&CK tactic.
the threat actor created a malicious file named ‘C:\Intel\svchost.exe’... attempting to mask the malware as benign activity... Additional executions of the Stowaway tunneling tool were also observed during this phase using the names ‘svchost.exe’, ‘tomcat.exe’, and ‘tomcat7.exe’.
Scanning the network using SoftPerfect Network Scanner (netscan.exe)
“Uses ... SoftPerfect Network Scanner / Advanced IP Scanner for host discovery.”
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A network-scanning tool used for subnet discovery and profiling hosts inside compromised victim environments.
Network scanning/enumeration tool used post-compromise to discover hosts/services and support lateral movement planning.
Legitimate network scanning tool used for internal discovery and reconnaissance to support lateral movement.
Commercial network scanning utility abused for internal reconnaissance, discovery of shared folders and services, and manual exploration of reachable systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.