Threat reporting and incident investigations show network service discovery has become a routine precursor to both ransomware deployment and state-backed intrusion activity. MITRE ATT&CK catalogs this behavior as technique T1046, covering port scanning, service enumeration, OS fingerprinting, and identification of exposed technologies such as Docker, Kubernetes, ESXi, and ICS services. CISA also warned that Chinese Ministry of State Security-affiliated actors rapidly scan for newly disclosed vulnerabilities on internet-facing systems and then exploit flaws including CVE-2020-5902, CVE-2019-19781, CVE-2019-11510, and CVE-2020-0688, often following up with tools such as Cobalt Strike, China Chopper, and Mimikatz.
Ransomware case studies show the same reconnaissance pattern inside victim networks. Hunt & Hackett reported that Advanced IP Scanner is frequently used during targeted intrusions and leaves useful Windows registry artifacts under HKEY_USERS\<SID>\SOFTWARE\famatech\advanced_ip_scanner, including scanned ranges and search history. Analysis of Conti source code found the malware derives internal subnets from the ARP table, scans hosts over SMB port 445, and enumerates shares with NetShareEnum, while Cisco Talos documented Maze operators using Cobalt Strike, RDP, WMIC, PowerShell, and 7-Zip during prolonged lateral movement and data theft before encryption. Separately, Intrinsec linked large-scale mass-scanning and brute-force traffic to BtHoster-associated bulletproof hosting networks that also hosted malware and command-and-control infrastructure, underscoring how scanning activity is supported by resilient criminal infrastructure.

Get the actors, campaigns, and ATT&CK mapping behind it.
10 events from the most recent confirmed update back to the earliest known activity.
On March 5, 2025, security analyst Jo Provost reported that CIPHER OPERATIONS DOO BEOGRAD, UAB Host Baltic, and Amwaj Alkhyr all announced prefix 81.30.107.0/24 in activity associated with suspected BGP hijacking. Intrinsec later cited this as part of its analysis of prefix movements tied to abusive infrastructure.
Intrinsec concluded with high confidence that Inside Network LTD (AS215476) and Skynet Network Ltd (AS214295) were operated by the bulletproof hosting provider BtHoster. The report also tied related infrastructure, upstream providers, and retained Iranian prefix descriptions to efforts to support scanning, brute-force activity, and malware hosting while obscuring attribution.
Intrinsec recorded around 61,724 attacks against its honeypots from SS-Net (AS204428) between February 17 and March 17, 2025. The report linked SS-Net to the 4Vendeta bulletproof hosting ecosystem with high confidence.
Intrinsec reported that its honeypots observed increasing attacks between February and March 2025 from small autonomous systems including Skynet Network Ltd and SS-Net-linked infrastructure. The activity included large volumes of brute-force and mass-scanning traffic.
Intrinsec reported that Inside Network LTD (AS215476), later linked with high confidence to BtHoster, was allocated in February 2024 and announced prefix 77.90.185.0/24. The report said this prefix had previously been announced by BtHoster LTD (AS198465).
Intrinsec said UAB Host Baltic had been used in 2024 for spam campaigns delivering XLoader malware. This was cited as part of the broader abusive infrastructure history surrounding networks later tied to BtHoster operations.
A public analysis of Conti ransomware source code described how the malware derives internal subnets from the ARP table, scans hosts on SMB port 445, and enumerates shares with NetShareEnum. The post also covered Conti's drive enumeration, process-killing logic, and a YARA rule with Conti-related strings.
Hunt & Hackett reported that Advanced IP Scanner was regularly used in targeted ransomware intrusions by actors including Conti, REvil, DarkSide/UNC2465, Ryuk/UNC1878, Egregor, Hades/Evilcorp, UNC2447, Dharma, and an unnamed Iranian actor. The article documented Windows registry artifacts and detection approaches for identifying the tool's execution and internal scanning behavior.
CISA, with FBI contributions, issued a joint advisory describing Chinese MSS-affiliated actors rapidly scanning for newly disclosed vulnerabilities and exploiting flaws such as CVE-2020-5902, CVE-2019-19781, CVE-2019-11510, and CVE-2020-0688. The advisory emphasized that these actors used common tools including Cobalt Strike, China Chopper, and Mimikatz against U.S. Government and other targets.
Cisco Talos published incident response findings on multiple targeted Maze ransomware intrusions in which the same adversary used Cobalt Strike, lateral movement, 7-Zip, PowerShell/FTP exfiltration, and then deployed Maze ransomware. Talos also linked at least two incidents to the same adversary and released related indicators of compromise.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 35 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
7 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcecocomelonc.github.io
Open sourcehuntandhackett.com
Open sourceus-cert.cisa.gov
Open sourceblog.talosintelligence.com
Open sourceintrinsec.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.