NetworkShareScanner is a propagation component used in the StopAndProtect cybercrime operation. It functions as an SMB/USB worm that enumerates accessible network shares and connected USB or other removable devices in order to copy itself or associated payloads beyond the initially infected host. It is deployed as part of a later-stage modular toolkit delivered through a multi-stage infection chain that begins with ClickFix-style fake CAPTCHA social engineering and PowerShell execution, followed by .NET loader stages.
Its primary role is lateral and adjacent spread rather than data theft or encryption. Within the broader StopAndProtect ecosystem, NetworkShareScanner complements other modules including the SilentEncryptor ransomware component, the SilentDataCollector stealer, a VBS-based spreader, a lock-screen module, and a custom victim-operator chat utility. The overall operation has targeted Windows environments and has relied heavily on compromised WordPress sites for malware hosting, command-and-control, and storage of stolen data. NetworkShareScanner is notable for extending infections through both enterprise-style shared resources and removable media, increasing reach inside victim networks and across nearby systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
NetworkShareScanner : ver SMB/USB, se propage via partages réseau ... T1021.002 — Remote Services: SMB/Windows Admin Shares (Lateral Movement)
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Propagation component acting as an SMB/USB worm, spreading through network shares and removable media.
Propagation component in the StopAndProtect toolkit that spreads via SMB/USB to other devices.
Propagation component that spreads laterally by enumerating SMB network shares and attached USB devices.
Propagation component that scans network shares and attached USB devices to spread laterally from the initially infected host.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.