Censys reported that a previously undocumented command-and-control framework dubbed SCOUT PROJECT was exposed on a public Linode host in Japan, revealing a threat actor’s source code, backdoor build system, and operational tooling. The exposed environment contained a C2 server, admin client, dropper builder, and payload, with malware communications using HTTP, fake PNG headers, and RC4-encrypted tasking. Censys said it did not identify matching SCOUT C2 servers deployed on the public internet at the time of its investigation.
Artifacts on the host showed the operator actively scouting and exploiting newly disclosed web application flaws, including CVE-2025-30208 in ViteJS, CVE-2025-3248 in Langflow, and CVE-2025-29927 in Next.js. Investigators found evidence that the actor identified nearly 100 potentially vulnerable Langflow targets, exfiltrated data from a Chinese NFT application using git-dumper, and attempted directory traversal attacks against asus.com, nasa.gov, and continental.com, indicating broad opportunistic targeting tied to exposed developer and AI workflow platforms.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
Screenshots in the exposed malware documentation indicate the SCOUT PROJECT malware existed since at least May 7, 2024. This is the earliest explicit date anchor tied to the toolkit in the source material.
After scanning for matching Flask Werkzeug servers and probing the /client_api endpoint, Censys reported it found no internet-exposed hosts matching the specific SCOUT C2 response patterns at the time of its scan. This reflects a distinct investigative finding rather than a new victim or attack.
Censys found the source code and backdoor build system for a previously undocumented command-and-control toolkit called SCOUT PROJECT exposed in a public directory on a Linode host in Japan. The archive contained a C2 server, admin client, dropper builder, and payload.
Censys observed evidence suggesting the actor successfully exfiltrated data from a Chinese NFT application using git-dumper. The source does not explicitly date the exfiltration.
Artifacts showed the operator scanning for CVE-2025-30208 affecting ViteJS and using a customized Nuclei template for CVE-2025-29927 in Next.js. No explicit date is given for these scans.
Artifacts in the exposed directory showed the operator scanning for CVE-2025-3248 in Langflow AI and logs indicated they successfully identified just under 100 vulnerable targets. The source does not provide a specific date for this activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.