ScanPortPlus
ScanPortPlus is a custom network scanning tool used by the intrusion cluster tracked by Palo Alto Networks Unit 42 as CL-UNK-1068 (assessed as a Chinese threat actor). Unit 42 describes ScanPortPlus as a Go-based scanner with both Windows and Linux versions, used by the attackers to scan compromised networks during post-compromise reconnaissance. Reported functionality includes IP address scanning, port scanning, and vulnerability scanning via command-line options. In observed intrusions, ScanPortPlus was among payloads executed in-memory as part of a DLL side-loading chain involving legitimate python.exe/pythonw.exe placed alongside a malicious loader (python20.dll) that deobfuscates shellcode and runs it within the Python process; the shellcode then decrypts/executes tools including ScanPortPlus (as well as other tooling like FRP and PrintSpoofer). No specific ScanPortPlus indicators of compromise (e.g., hashes, filenames, C2 endpoints) are provided in the supplied content.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Another tool in CL-UNK-1068's arsenal is a custom Go-based network scanning tool named ScanPortPlus, for which it has developed both Linux and Windows versions...
Techniques & procedures
2 distinct techniques documented for this family, organized by ATT&CK tactic.
Execution
1 technique
Execution
Stealth
1 technique
Stealth
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom network/port scanning tool used for internal reconnaissance.
Custom Go-based port/network scanning utility used for internal reconnaissance across both Windows and Linux environments.
Custom Go-based multi-platform network scanner (Windows/Linux) supporting IP/port scanning and vulnerability scanning for internal discovery.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.